mu.ai Security Summary

Last updated: 2026-06-01

Architecture: transit-only

Prompts and attachments are processed in memory to make a friction decision and are then discarded. They are never written to disk, never written to backups, never written to log files. RAM lifetime is the lifetime of the request (typically <1 second; up to 5 minutes if a friction challenge is held open awaiting user reply).

The only data we persist is mastery signal: classifier output (domain + intent), friction decision, pass/fail, reasoning quality score, attachment count + MIME types, token counts, and timestamps.

Authentication & sessions

Encryption

Access controls

Third-party processors

Data subject rights

Compliance posture

Contact

For security questionnaires, pilot scoping, or DPA requests: privacy@mu-ai.app.