Our posture at a glance
We design production systems around the sensitivity of the data, the consequence of failure, and the obligations supplied by the client. This page describes our engineering approach; it is not a claim that Michai Media holds SOC 2, ISO 27001, HIPAA, FedRAMP, StateRAMP, or other independent certification or authorization.
We can design minimum-necessary access, retention boundaries, review gates, and vendor selection around a client's documented obligations. HIPAA applicability and BAA coverage are confirmed during procurement, not assumed.
Access, change, monitoring, recovery, and evidence requirements can be mapped to a client's control framework. Michai Media does not represent itself as independently SOC 2 certified.
Data minimization, consent, deletion, retention, and processor terms are scoped to the product, users, jurisdictions, and selected vendors.
When isolation or residency requires it, we can scope deployment into client-controlled infrastructure instead of a studio-owned environment.
Controls we run
Infrastructure partners
We use established infrastructure and service providers such as Vercel, Supabase, Anthropic, OpenAI, Stripe, and Telnyx when they fit the engagement. Available certifications, data regions, retention controls, and contractual terms vary by provider and plan, so we verify the exact combination during architecture and procurement.
Data handling
Client data is processed only for the agreed scope. Retention, deletion, access, and vendor processing terms are documented for the engagement, with additional safeguards added when the data or governing agreement requires them.
Model interactions route use business API products and available retention controls selected for the engagement. We document provider behavior rather than assuming every model, plan, or endpoint has identical terms.
Audit and human oversight
We define which model calls, tool actions, approvals, and administrator changes need evidence based on the system's risk. Sensitive or irreversible actions receive explicit authorization and human review instead of blanket autonomy.
Incident response
Security reports route through the contact published in our security.txt file. Client notification windows, escalation contacts, investigation duties, and post-incident reporting are defined in the applicable agreement and governed by law.
Document requests
The following are available on request with a signed MSA or NDA: security questionnaire responses, system and data-flow diagrams, deployment architecture, subprocessors, and relevant operating procedures. DPA or BAA requirements are evaluated with counsel and the selected vendors before we make a contractual commitment.
