Irmu
Legal

Security

How the platform is built, monitored and defended.

Last updated 2026-08-27

Infrastructure

The platform runs in hardened cloud environments with network segmentation between the control plane, the render fleet and the proxy layer. All traffic is TLS 1.3; data at rest is encrypted with AES-256.

Access control

Employee access follows least privilege and requires multi-factor authentication. Production access is limited to the people who need it and is logged.

Application security

Dependencies are scanned continuously and changes go through peer review and automated testing. We have not yet completed a third-party penetration test or a formal certification such as SOC 2 or ISO 27001, and we will not claim otherwise during a security review.

API keys are stored hashed, can be scoped per environment, and are revocable instantly from the dashboard.

Monitoring and response

We run automated alerting on availability, error rates and anomalous usage, and follow a documented incident response process with defined severity levels. Incidents that affect customers are posted on the status page with a follow-up write-up.

Reporting a vulnerability

Email security findings to info@irmu.com with a description, reproduction steps and any proof-of-concept material. We acknowledge reports within two business days and will not pursue legal action against researchers acting in good faith who avoid privacy violations, service degradation and access to data belonging to others, and who give us reasonable time to fix an issue before disclosure.

Out of scope: volumetric denial-of-service testing, social engineering, automated scanner output without demonstrated impact, and issues in third-party services we do not control.

Irmu LLC · 5437 Cove Cir, Naples, FL 34119, United States · info@irmu.com

Start building with Irmu today

1,000 free credits every month, no card required. Every API, every integration, one key.