Security claims should be
evidence, not slogans.

Mining Terminal security infrastructure

Our current posture, stated plainly.

This page distinguishes controls operating today from work in progress and independent assurance we do not yet claim. It was last reviewed on 17 July 2026.

Mining Terminal uses third-party infrastructure and AI providers. We do not claim dedicated per-customer infrastructure, EU-only processing, or a completed certification unless a customer agreement expressly says so.

01
In place

Platform protection

The application is served through Cloudflare and uses HTTPS, HSTS, anti-framing, content-type, referrer, and browser-permission headers. Protected application routes are access-gated, and security checks and rate limits are applied at the edge and API layers.

02
In place

Authentication and API access

User authentication is provided through Clerk. API access uses bearer keys stored as cryptographic hashes; keys can expire or be revoked, and access is checked against the customer, product, module, rate, and usage entitlements configured for that key.

03
In place

Data storage and suppliers

Mining Terminal uses contracted infrastructure and service providers, including Cloudflare, Supabase, Clerk, AWS, Stripe, and Resend. These providers process only the data needed for their role. We are documenting our complete subprocessor register, data locations, transfer mechanisms, and retention settings as part of our formal privacy program.

04
In place

AI processing

Nara is an AI-generated research service. Prompts, selected Mining Terminal evidence, and outputs may be processed by contracted model-inference providers, including Together AI and Fireworks AI, and conversation history may be stored to provide the service. Users should not submit sensitive personal or confidential information unless their organization has authorized it.

05
In place

Research controls

Product-facing records pass release and visibility gates before they are exposed. Source references and as-of dates are provided where the underlying record supports them. Source coverage and extraction are not perfect: customers must review primary materials before making financial, legal, technical, or operational decisions.

06
In progress

Privacy and customer content

Mining Terminal does not sell personal information or share it for cross-context behavioural advertising. We are formalizing retention schedules, data-subject request handling, vendor reviews, processing records, and international-transfer documentation. AI sessions can be deleted from the product.

07
In progress

Security operations

Access reviews, incident response, backup and restore evidence, secure-development checks, dependency and secret management, and vulnerability handling are being consolidated into a documented security management program. Control evidence is available to customers only when it has been collected and verified.

08
Not claimed

Independent assurance

Mining Terminal does not currently claim SOC 2 attestation, ISO 27001 certification, PCI DSS certification, a completed independent penetration test, or compliance with every privacy or cybersecurity framework. These are separate assurance activities and will be stated here only after the relevant independent work is complete.

09
In place

Vulnerability reporting

Please report suspected vulnerabilities to security@miningterminal.com. Include reproduction steps and impact where possible. Do not access, alter, or retain data that does not belong to you. We will review good-faith reports and coordinate remediation and disclosure where appropriate.

Security and privacy questions.

Procurement teams can request the current security questionnaire, subprocessor information, and available control evidence. We will identify what is verified, what is planned, and what is not available.

Contact security