Trust and security sit at the core of what Pirros does
We hold your firm’s details, families, and specifications — the work your practice is built on. The bar has to be the same one you hold your other enterprise software to. Here is where we are certified and where we comply, what we commit to, and the answers your IT team asks for most.
Our SOC 2 Type II certification is issued and audited by an outside firm.
Verified by outside auditors
Not a list of intentions. Everything in this first group is something an outside auditor, an independent penetration tester, or a named sub-processor stands behind. What we attest ourselves is listed separately below.
SOC 2 Type II
Certified and audited against the same standard your other enterprise vendors are held to, with controls monitored continuously through Drata.
Hosted on AWS in the United States
Serverless, across multiple availability zones. AWS is a named sub-processor on our published list.
Authentication managed by Auth0 by Okta
SAML single sign-on and role-based access control. Pirros never stores or handles your passwords.
Encrypted at rest and in transit
AES-256 at rest, TLS 1.2 or higher in transit, with key management for production encryption keys. Insecure HTTP requests are redirected to HTTPS.
Independently penetration tested
November 2025, against the OWASP Top 10, across the full production application. Zero critical, zero high, and zero medium findings; three low, all addressed.
21 security policies, reviewed annually
Reviewed under our SOC 2 program, covering access control, encryption, incident response, and business continuity.
- SOC 2 Type II
- Drata continuous monitoring
- AWS United States
- Auth0 by Okta
- AES-256 at rest
- TLS 1.2+ in transit
And what we attest ourselves
These are our own record, our own testing, and our own compliance positions — not an outside body’s findings. We will put any of them in writing for your assessment.
- No security incident to date
- 99.9% monthly uptime target, excluding scheduled maintenance
- Multi-AZ failover, tested
- GDPR compliant
- CCPA compliant
Four commitments, in plain language
Standards and audits describe how we run. The four below describe what you get, and what we are on the hook for.
Your content stays yours
Firm data is isolated. No other firm can see, search, or retrieve your details, families, or specifications — and inside your firm, your admins decide who can reach what.
Your data never trains the model
Nothing your firm puts into Pirros changes the engine another firm uses. Where Mira draws on your content, that context stays in your workspace and is deleted when you leave.
A person always decides
Mira suggests and flags. It does not issue, stamp, or seal anything, and professional responsibility stays with your licensed staff.
You can leave with everything
Full export at any time, in native formats, at no cost. On termination we delete your data within 60 days of a written request.
How we handle personal data — what we collect, who we share it with, and the rights you can exercise — is covered in our privacy policy, alongside the full sub-processor list.
Only what a question needs reaches the AI
Mira partners with you across Pirros, working where your content already sits. Here is exactly what that means, and exactly where the boundaries are.
Mira reads your content in place.
When Mira inspects your firm’s content — details, families, specifications, parameters — it reads it where it already lives in Pirros. Only the specific information needed to answer the question at hand goes to the AI model, and nothing else is sent.
Mira can’t reach files you haven’t approved.
File access is restricted to an approved-folder list. The first time Mira needs a new folder, the user gets an Allow or Deny prompt, and only what they approve is remembered. Anything outside that list is refused.
No other firm can see your data.
Each Mira session is bound to the user who created it and no other user can see it.
Pirros does not train AI models on your data.
We don’t use your conversations or your content as training material.
Mira does build context about your firm.
So it answers the way your firm works rather than the way a generic tool would. That context is scoped to your workspace and visible only to your people.
Firm context leaves when you do.
If you stop working with Pirros, that context is deleted with the rest of your data. The AI model is left exactly as it was.
A person approves every output.
Mira suggests and flags. It does not issue, stamp, or seal anything. Your licensed staff make the call.
What your IT team will want to know
Can another firm on Pirros see our details?
Do you use our drawings or details to train AI models?
Will Mira learn how our firm works?
Who at Pirros can see our data?
Has Pirros been penetration tested?
Have you ever had a security incident?
What happens to our data if we cancel?
Which model providers sit behind Mira?
Can we review your SOC 2 Type II report?
Reviewing Pirros for your firm?
Get in touch with our security team and we will work through your assessment with you. Our privacy policy covers how we handle personal data and lists our Data Protection Officer.