A plain-language view of what MIRMC has implemented, what remains gated, and what we do not claim yet.
Enterprise-capable · evidence in progress
Enterprise architecture without pretending every procurement box is already closed.
MIRMC publishes this registry from the same source used by engineering checks. Implemented controls stay distinguishable from planned controls, and certifications are never inferred from architecture alone.
This is an engineering maturity statement, not a security certification, legal opinion or contractual SLA.
5
Implemented
11
Controlled
6
Planned gaps
2
Not certified
Evidence snapshot date: 2026-08-25
Control registry
What is real today
platform
Cloudflare production runtime
Implemented
Cloudflare Workers is the canonical production origin used by auth redirects and public SEO metadata. Candidate evidence records exact source/version identity and public smoke checks.
MIRMC publishes a private reporting channel, responsible-testing boundaries and a standard security.txt discovery record without pretending to operate a bug-bounty or guaranteed remediation SLA.
Repository evidence
src/routes/$lang.security.tsx
public/.well-known/security.txt
identity
TOTP MFA foundation and AAL2 challenge
Controlled / gated
MIRMC contains TOTP enrollment plus a shared post-login AAL1-to-AAL2 challenge for accounts that already have a verified factor. Privileged Agency billing and guarded Command Center mutations also have server-side assurance gates.
Repository evidence
src/routes/$lang.mfa.tsx
src/routes/$lang.mfa-setup.tsx
src/lib/mfa-navigation.ts
src/lib/post-auth-destination.ts
src/lib/admin-command-assurance.server.ts
scripts/check-enterprise-identity.ts
billing
Server-authoritative billing convergence
Controlled / gated
Stripe redirects do not grant a plan. Signed webhooks, server-owned price mappings and exact approved transitions are required before subscription state converges.
Repository evidence
docs/AGENCY_SAAS_STRIPE_BILLING.md
supabase/functions/agency-stripe-webhook/index.ts
scripts/check-agency-saas-billing.ts
operations
Tenant and operational audit trails
Implemented
Tenant mutations and commercial transitions append structured organization audit evidence. Guarded Command Center mutations preserve authorization denials and execution lifecycle evidence, and a staged AAL2 owner/admin export boundary adds bounded JSON/NDJSON security workflows, explicit browser-origin controls and per-page SHA-256 integrity receipts.
A public localized status surface performs a fresh production health probe and exposes exact candidate smoke evidence while explicitly separating live health from historical uptime and contractual SLA claims.
Repository evidence
src/routes/$lang.status.tsx
docs/ENTERPRISE_OPERATIONAL_STATUS_SLO_V1.md
src/data/cloudflare-candidate.generated.ts
operations
Operational resilience operating model
Controlled / gated
MIRMC now defines machine-readable incident severities, response roles, engineering-only RPO/RTO targets and an isolated restore-drill evidence protocol. Numeric targets remain unverified and non-contractual until actual drill receipts exist.
MIRMC publishes a code-backed provider/integration register that distinguishes core runtime dependencies from conditional and optional services. It deliberately does not pretend to be a signed legal subprocessor schedule or data-residency guarantee.
Repository evidence
src/lib/enterprise-provider-register.ts
src/lib/enterprise-provider-register.test.ts
src/routes/$lang.providers.tsx
src/data/runtime-env-inventory.generated.ts
operations
Four-eyes publication governance
Controlled / gated
MIRMC now contains a staged tenant-scoped publishing authority with current-session AAL2, maker/checker separation, two independent approvals for production, approval expiry, exact source-commit binding and a service-only Cloudflare release-receipt boundary. Production activation is not claimed yet.
Agency Overview now contains a staged aggregate-only multi-site operations surface for repository coverage, autonomy, preview approvals, domains and publication governance. The snapshot is tenant-authorized and does not expose raw customer/project rows.
MIRMC now contains a staged tenant-scoped retention control plane with bounded category policies, AAL2 administration, legal holds with creator/releaser separation and a service-only deletion-eligibility gate. Automatic deletion is off by default and no production purge is claimed.
MIRMC now maps eight code-backed processing activities to canonical provider boundaries, data classes, data subjects, retention categories and residency evidence states, and can build a procurement JSON packet from canonical registries. The map is engineering evidence only: no DPA, legal role, transfer mechanism, residency guarantee or compliance certification is inferred from source.
MIRMC now contains a staged SAML SSO initiation/callback foundation plus explicit provider-UUID-to-organization binding and negative cross-tenant guards. Production remains planned because no live IdP has been registered and verified, and OIDC is not claimed implemented.
A tenant-scoped SCIM 2.0 Users foundation, hash-only organization credentials, SAML-bound first-login linking, AAL2 control plane and optional atomic ETag preconditions are staged. Production remains planned until a real IdP and SCIM client canary succeeds.
Agency billing and guarded Command Center mutations now validate request-session assurance server-side and reject enrolled users whose session can reach AAL2 but is still AAL1. Command Center MFA denials are recorded without persisting access tokens or TOTP values. Mandatory enrollment by sensitive role and universal RPC/RLS enforcement remain open enterprise work.
Repository evidence
supabase/functions/_shared/agency-stripe.ts
src/lib/admin-command-assurance.server.ts
src/lib/admin-command-execution-guard.server.ts
src/lib/admin-command-assurance.server.test.ts
scripts/check-enterprise-identity.ts
src/lib/enterprise-saas-readiness.ts
operations
Evidence-based release authority
Controlled / gated
Cloudflare candidate identity and fresh runtime probes are the production evidence boundary. A missing or failed hosted check is never silently converted into success.
Repository evidence
docs/ENTERPRISE_RELEASE_AUTHORITY_V1.md
src/data/cloudflare-candidate.generated.ts
README.md
security
Production network access enforcement
Planned / gap
MIRMC has source-closed Network Gateway v18 controls with all nine registered privileged surfaces network-evaluated and no known source direct RPC bypasses. Production ENFORCE remains planned because coordinated secrets, staging conformance, measured canary, runtime evidence and explicit activation have not been verified.
The August 25, 2026 audit found main unprotected and without required status checks. CODEOWNERS and a staged ruleset policy are now prepared, but GitHub settings must enforce them before this control becomes implemented.
Live operational transparency now exists and an incident operating model is defined, but historical uptime, historical incident evidence and contractual uptime/remedy commitments are not yet claimed as complete.
Repository evidence
src/lib/enterprise-saas-readiness.ts
docs/ENTERPRISE_OPERATIONAL_STATUS_SLO_V1.md
docs/ENTERPRISE_INCIDENT_OPERATIONS_V1.md
compliance
SOC 2
Not certified
MIRMC does not claim SOC 2 certification in this trust registry.
MIRMC now has explicit engineering RPO/RTO targets and an isolated restore-drill protocol, but this audit still does not claim completed recurring DR evidence or verified achievement of those targets.
Repository evidence
src/lib/enterprise-saas-readiness.ts
src/lib/enterprise-operational-resilience.ts
docs/ENTERPRISE_OPERATIONAL_STATUS_SLO_V1.md
docs/ENTERPRISE_DR_RESTORE_DRILL_V1.md
Procurement conversation
Need evidence for a security or vendor review?
We can separate implemented controls, planned controls and customer-specific contractual requirements instead of mixing them into marketing claims.