Skip to content

Security

Content leaves the machine already unreadable

A backup multiplies the copies of your most sensitive files. With MIRRO those copies never leave your walls — and here is exactly what protects them where they sit.

Encrypted at the source

Packages are encrypted on the originating machine, as they are written, before any transfer. What crosses the network and what sits in the vault is already unreadable without your company’s key.

Refusal over compromise

If encryption is required and the key isn’t available, the agent halts the run and reports it. There is no “send in the clear” fallback — a configuration mistake cannot cause a silent leak.

The key is never left in the clear

The company encryption key is delivered wrapped at authentication and is never written in the clear on the machine. It appears in no administration interface.

Time-limited access

Agents and administrators authenticate with short-lived signed tokens. Refresh tokens are distinct from access tokens and cannot be used in their place.

Verifiable state

A file is marked as backed up only after the server confirms its batch. Run logs keep what went out, what failed and when — enough to answer an auditor with dates.

Per-company isolation

Each company has its own accounts, paths, key and vault. An agent only ever sees the scope of the company it belongs to.

Our practices

What SIIO commits to

We don’t read your files
Backed-up content is accessed only at your request, as part of a restore or a diagnostic you opened.
We test restores with you
At least once a year, we walk you through a real restore test. A backup never restored is a hypothesis, not a guarantee.
Your data never leaves your walls
The MIRRO service and the vault install on your equipment. Your files pass through no SIIO infrastructure and no third-party cloud provider. Our technical support, on the other hand, stays in Québec.
We document for your auditors
Algorithms, parameters, retention and detailed architecture are provided in a technical dossier, on request, to you and your auditors.

Law 25 and retention

MIRRO is a processing tool: the information backed up stays under your company’s responsibility, and since everything sits on your own equipment, the question of data residency never arises. We give you what you need to meet your obligations — configurable retention periods, access logs, deletion on request, and a description of the processing to attach to your register.