Account protections
Miorly ID uses authenticated sessions, email verification and recovery flows, rate limiting for sensitive actions, server-side access checks, and user-scoped database access controls.
Available account controls include reviewing sessions, managing passkeys where supported, updating privacy preferences, exporting account data, and requesting account deletion.
Protect your account
Use a unique password or a passkey, protect access to your email inbox, and review active sessions if you do not recognise a sign-in. Never share one-time codes, recovery links, or wallet signatures with another person.
Check the domain before entering credentials. Miorly staff should never ask for your password or private wallet keys.
Suspected compromise
If you suspect an account compromise, change your password, remove unfamiliar sessions, and review connected sign-in methods. Use a secure device and email account before restoring access.
A dedicated security reporting address and incident response process must be published before public launch. Do not include passwords, private keys, or access tokens in a report.
Responsible disclosure
Security testing must be authorised and non-destructive. Do not access another user’s information, disrupt service, run denial-of-service tests, or publish an exploit before Miorly can assess it.
Miorly should publish a vulnerability disclosure policy, reporting channel, and response expectations before opening the service broadly.