Enterprise Attestations
By checking the boxes below, you confirm that you have read, understand, and agree to all enterprise commitments:
View all attestations
- User Consent: We will only query MIR for users who have knowingly linked their account through MIR's linking flow.
- Policy Decisions: We understand MIR provides signals for policy decisions, not verdicts. Final authorization decisions remain with our systems.
- Proportionate Response: We will use MIR signals proportionately -- applying appropriate friction (step-up auth, manual review) rather than blanket denials.
- Absence Is Neutral: We understand that lack of MIR history is not evidence of risk and will not be treated as grounds for denial.
- Data Security: We will handle MIR data according to enterprise security standards and our data protection policies.
- No Resale: We will not sell, share, or redistribute MIR data to third parties.
- Audit Compliance: We will maintain appropriate logs of policy decisions for compliance and user inquiry purposes.
- Policy Artifact: We will produce and maintain a written policy artifact that maps MIR recommendations to operational responses based on action class, stakes, and our own organizational requirements. We will not pure-pass-through MIR recommendations as authorization decisions.