Security
Last updated: July 2026
The security of our clients' data is at the heart of Miravela AI. Here are the technical and organisational measures we maintain.
Encryption
All data is encrypted at rest (AES-256) and in transit (TLS).
Per-client isolation
Every client is strictly isolated from the others at the database level (row-level security). Files are stored in private buckets, served only through short-lived signed links. No client can access another client's work.
Hosting in the European Union
Data and files are hosted in the EU (Supabase, Paris region). The application runs on Vercel. See the sub-processor list.
Access management
Least-privilege access, strong authentication (passkeys and Google sign-in) for the admin workspace, and time-limited magic-link access for clients.
Backups
Data is backed up regularly, with tested restoration.
Human review
Nothing is delivered automatically: every selection goes through a human review before it reaches the client.
No-train commitment
Your briefs, references, logos, products and generated visuals are never used to train any AI model — not ours, not a third party's. The model providers we use run in API mode with no training retention. Your data stays your data.
Asset provenance
Every visual produced on the platform is traceable: model, prompt, generation date and cost are stored with the asset. Client deliveries carry a transparency notice stating the content is AI-generated.
Audit log
Sensitive operations (generations, deletions, exports, shares, API access) are recorded in a timestamped audit log available to the administrator.
In case of an incident
In the event of a data breach, we notify affected clients without undue delay (and within 48h at the latest), in line with the GDPR.
Contact us
For any security question, or to request our Data Processing Agreement (DPA): info@miravela.ai.