Security & privacy
Built for the scrutiny healthcare deserves.
Mimo works with legal documents and protected health information. Here is exactly how we treat both — and where your compliance office can dig deeper.
- Business associate agreement, always
- We sign a BAA with every customer before any PHI is processed. No exceptions, no 'lite' tiers without one.
- Human-in-the-loop by design
- Mimo drafts; a credentialed person reviews every field and submits every record. There is no mode in which Mimo submits on its own. This is an architectural property, not a setting.
- Encryption in transitPending engineering confirmation
- All data moving between the extension, Mimo services, and model providers is encrypted in transit using TLS.
- Minimal retentionPending engineering confirmation
- Mimo keeps no patient data beyond what processing requires. Drafts exist to be reviewed, then leave the system on your schedule.
- No model training on customer dataPending engineering confirmation
- Customer data — including PHI — is not used to train AI models.
- Audit trailPending engineering confirmation
- Every record carries a trail of what Mimo drafted, what the user edited, and what the user submitted — the evidence base for your compliance office and ours.
- User-initiated, one record at a time
- The agent runs when a signed-in user starts it, on the record they're working, in their browser session with their credentials. Mimo is an assistive tool in the user's hands — closer to a very capable autofill than to unattended automation.
Items marked “pending engineering confirmation” describe our design intent and are being finalized in documentation with our engineering team; ask us for the current state during your security review. This page describes how Mimo is designed to operate — it is not legal advice, and your organization’s own review governs.
Put your security team in front of ours
Book a demo and bring your compliance questions — we'd rather answer them in week one than in month six.