Miorly ID
Legal & Safety Center

Security Center

How Miorly ID protects accounts and what to do if something looks wrong.

Updated 3 August 20262026-08-03

This page describes the current security design at a high level. It is not a guarantee against every risk, and it does not publish sensitive implementation details.

1.

Account protections

Miorly ID uses authenticated sessions, email verification and recovery flows, rate limiting for sensitive actions, server-side access checks, and user-scoped database access controls.

Available account controls include reviewing sessions, managing passkeys where supported, updating privacy preferences, exporting account data, and requesting account deletion.

2.

Protect your account

Use a unique password or a passkey, protect access to your email inbox, and review active sessions if you do not recognise a sign-in. Never share one-time codes, recovery links, or wallet signatures with another person.

Check the domain before entering credentials. Miorly staff should never ask for your password or private wallet keys.

3.

Suspected compromise

If you suspect an account compromise, change your password, remove unfamiliar sessions, and review connected sign-in methods. Use a secure device and email account before restoring access.

A dedicated security reporting address and incident response process must be published before public launch. Do not include passwords, private keys, or access tokens in a report.

4.

Responsible disclosure

Security testing must be authorised and non-destructive. Do not access another user’s information, disrupt service, run denial-of-service tests, or publish an exploit before Miorly can assess it.

Miorly should publish a vulnerability disclosure policy, reporting channel, and response expectations before opening the service broadly.

Reference material