Legal
Security Overview
Last updated: September 8, 2026 · MF Automations LLC
How we protect Customer Data. If you are evaluating us and need something this page does not answer, ask — we would rather answer directly than have you guess.
Infrastructure
- Production compute and storage run on hardware MF Automations owns and operates in the United States. Customer Data is not stored outside the US.
- Public web properties are served through Cloudflare, with TLS enforced and DDoS and bot protection enabled.
- Remote administrative access is over an authenticated private network overlay rather than the public internet.
Data protection
- TLS 1.2 or higher for all data in transit, with HTTP Strict Transport Security enabled.
- Credentials and API keys are held in a dedicated secrets store, never in source control. Every code push is automatically scanned for secrets before it can land.
- Encryption at rest for sensitive stores.
- Call recordings are retained 90 days by default and can be disabled per account.
Access control
- Named individual accounts; no shared logins for production access.
- Multi-factor authentication on administrative and cloud provider accounts.
- Least-privilege access, reviewed on personnel change.
- Access to Customer Data is limited to personnel supporting or securing the Services, and is logged.
Development and change management
- All production changes go through version control and peer review; no direct edits to running systems.
- Automated checks — secret scanning, syntax and lint validation — gate every change before it can be merged.
- Changes are deployed by automation, with rollback available.
Monitoring and response
- Service health and access monitoring with alerting.
- Documented incident response process. We notify affected customers of a personal data breach within 72 hours of becoming aware, per section 7 of our DPA.
- Backups run on a regular schedule and are retained for a limited window before rotation.
What we do not claim
We are not currently SOC 2 or ISO 27001 certified, we do not offer a HIPAA Business Associate Agreement by default, and we are not PCI DSS certified — do not send us cardholder data. We would rather say so plainly than imply otherwise.
Reporting a vulnerability
Email [email protected]. We will acknowledge within 2 business days. We will not pursue legal action against good-faith security research that respects user privacy, avoids service disruption, and gives us reasonable time to remediate before disclosure.
MF Automations LLC · 233 NE 27th St, Miami, FL 33137 · [email protected] · (305) 965-9624