Product controls
Subject isolation
Every authenticated/v1 request is scoped to the API-key owner. Within that account, the user field resolves to an isolated Subject. A developer cannot use an API key to read another account’s Subjects.
Use a stable, non-sensitive identifier for user; do not put an email address, medical record number, or other direct identifier in the field unless your data policy requires it.
API credentials
API keys use themb_live_* format. The full secret is returned only when the key is created; the service stores a hash, and the developer console then shows only the key prefix. Revoke a key immediately if it may have been exposed.
Retention and deletion
The API exposes explicit controls for each storage surface:DELETE /v1/sessions/{id} does not delete stored response objects. For the exact behavior of every deletion path, see Data Lifecycle and State & Memory.
Traceable outputs
Agent responses can includetool_steps, health_records, and citations so applications can inspect the tool calls and evidence returned for an answer. These fields are an execution trace, not a guarantee that private model reasoning or every internal operation is exposed.
On the Agent API, store:false prevents the response object and conversation thread from being retained after the request. It also keeps that turn from contributing to the Subject’s stored memory.
Regional processing
The regional environments use separate hosts and storage. Data sent toapi.mirobody.ai/v1 is processed in the global environment; data sent to api.mirobody.cn/v1 is processed in the China-region environment. Do not switch regions for the same Subject unless your own compliance review permits the resulting data transfer.
Regulatory review
For a US healthcare workload, review your obligations under the HIPAA Privacy and Security Rules and confirm whether a Business Associate Agreement (BAA) is required for your deployment. Product capability alone does not make a workload HIPAA-eligible — the applicable agreements and your own safeguards must also be in place. If you use the China-region deployment (api.mirobody.cn), your workload may additionally be subject to Chinese data-protection law:
Security and compliance package
For a security questionnaire, architecture review, data-processing terms, or the current availability of a DPA, BAA, or independent assessment, contact Mirobody Support. Obtain the applicable documents before sending regulated production data.See also
- Data Lifecycle — retention, session cleanup and Subject offboarding.
- API Overview — the
userfield and how tenants are isolated. - Regions Overview — where each cluster processes data.