MimiDesk

Security

Boring on purpose

Customer mail is the most sensitive thing a company can hand to software. This page states what MimiDesk actually does — and only that.

EU residency

Every resource runs in Microsoft Azure's North Europe region (Ireland) — the application, the database, the storage.

Private networking

Databases and storage accept no public connections: private endpoints only, TLS 1.2 or newer enforced.

Isolated environments

Production is its own cell — its own network, database and storage, with no route to or from anything else.

Workspace isolation

Every row is scoped to its workspace throughout the product, enforced on the server — a screen never grants what the server would refuse.

A real audit trail

Actions that matter write to an audit log — including every AI send and every AI refusal — so "what happened" is a query, not a reconstruction.

AI off by default

No conversation content reaches a model until a workspace admin turns Mimi on, told exactly what is sent and where.

Privacy by structure

Private means the code cannot do otherwise

Personal mailboxes are private by default, and the analytics a lead sees are computed from metadata — volumes, timings, ageing — honouring each person's consent setting.

Internal notes live in a table the outbound send path cannot reach, so a private remark about a customer cannot be mailed to that customer by any bug in a WHERE clause. Where privacy matters, we prefer structure over policy.

Leads see metadata — volumes and timings — never message bodies — stylised illustration.

Your data, your exit

Leaving is a capability, not a negotiation

A workspace's data can be exported — every table that belongs to it, with the completeness enforced by the build, not by a checklist. Erasure on request runs as a recorded engine whose steps can be verified afterwards.

Retention promises are only ever written where the code keeps them; the legal documents are checked against the product, in both directions.

Export and erasure are product engines with verifiable steps — stylised illustration.

No badges until we hold them

You won't find compliance logos on this page until the certifications behind them are actually held. What you will always find is a plain statement of what the product does — and a person who answers.

Security questions and vulnerability reports: hello@mimidesk.com — thank you for telling us first. Data protection terms live in the DPA.