Security posture — Mungry LLC
Purpose
This page explains how Mungry LLC approaches security in two places owners actually care about:
- This website - the corporate site you are on now, including inquiries and admin tools.
- Client work - how we ask for access, handle secrets, and design control into systems we help put into production.
Security is part of how we deliver. We do not keep it as a separate brochure. We write practices we can keep as a small firm: scoped access, named people, plain logs, and clear ownership on your side.
This page is a public security note. It is not an SOC report, a penetration-test letter, or a claim of SOC, ISO, HIPAA, FedRAMP, or any other certification. We do not use “military-grade” language. Framework names appear here only when a matching report or attestation is linked from this page.
This page does not create a service-level agreement and does not amend any master services agreement, statement of work, or other signed contract.
This website
Transport and hosting
- Traffic to this site is served over HTTPS.
- Hosting and related infrastructure run on cloud providers we contract for the site. We keep the public surface small: marketing pages, legal notes, and inquiry forms.
Inquiries and admin access
- Contact forms collect the fields you submit (name, work email, organization, role, brief). We ask you not to put passwords, keys, payment data, or regulated material in a first note. See Privacy.
- Admin tools for this site (if enabled) are limited to named administrators. Default bootstrap access is controlled by the firm; accounts can be suspended. We do not treat public registration as a path to admin.
- Ordinary server and security logs (IP, user agent, request path, status) support operations and abuse response. Retention is short unless a security investigation needs longer.
What we do not put on this site
We do not ask for client production credentials through the public site. Engagement access is set up under a scoped agreement, not through a marketing form.
Client engagements
Access is scoped to the work
When we work in your environment:
- Access is limited to the systems and time window the engagement needs.
- We prefer named accounts (yours or contractor accounts you control) over shared passwords.
- We prefer least privilege: only the roles required for the milestone in play.
- When the engagement ends, access tied to it should end with it, unless you renew it in writing.
Secrets stay under your control
- Credentials, API keys, and vault material for your systems stay in your control plane (your identity provider, your secret store, your cloud account) unless a written instrument says otherwise.
- We do not ask you to paste production secrets into chat, email, or this website.
- If temporary shared access is unavoidable, we agree in advance who holds it, how it is rotated, and when it is revoked.
Audit trail over folklore
- Changes that matter should leave a record someone on your team can read later.
- Shared “one password in a sticky note” patterns are a last resort we work to replace, not a default.
Systems we help you put in production
For AI-enabled workflows and agents we help design or build, we treat security controls as part of delivery - not something bolted on after a demo.
The table below lists examples of practices we often recommend. They are not warranties that every engagement includes every row. The controls that apply to your project are the ones written into the signed engagement plan (or MSA / SOW), not this page.
| Example practice | What it can mean for you |
|---|---|
| Company logins | Prefer your Microsoft or Google (or other) single sign-on so access follows your people. |
| Permissions by person and role | Who can see and do what is explicit; departing staff can be cut off in one place. |
| Spend caps and alerts | Model and automation spend has a budget you set, with warning before the limit. |
| Pause control | Someone on shift can stop an automation without waiting on us. |
| Activity log | Important actions are recorded so you can answer “what did it do?” |
| Evaluation before go-live | Representative cases, including failure cases, before customers or staff rely on the system. |
| Kill paths and escalation | Agents that take actions have a written list of allowed tools and a path for unusual cases. |
Where those examples are selected for your work, the goal is the same: owners stay in charge of data, spend, and accountability.
People, vendors, and products
- People. Delivery staff and contractors working on your account are expected to follow the access and secret rules above.
- Vendors. Hosting, email delivery, and similar processors for this website act on our instructions; see Privacy for the categories we use. Client-side cloud and model vendors stay under your agreements unless we introduce a tool under a separate written arrangement.
- Verndr and other suites. Packaged products marketed under Verndr (and future suites) publish their own customer-facing security, privacy, and terms on their product sites. This page does not replace those. Vulnerability reporting for Verndr follows the channel on verndr.com.
How to report a problem
Suspected vulnerability in this website or another Mungry-owned corporate property:
Please:
- Describe the issue and how to reproduce it at a high level.
- Do not include third-party personal data, customer files, or a full exploit chain that depends on stolen data.
- Give us a reasonable window to investigate before public disclosure.
Product-specific reporting for Verndr follows the channel published on verndr.com.
Related pages
| Page | What it covers |
|---|---|
| Privacy | Personal information on this website |
| Terms of use | Rules for using this website |
| Cookies | Cookies and similar tech on this site |
| Responsible AI | Operating principles for services work |
| verndr.com | Product terms, privacy, and security for Verndr |
Contact
Security reports: security@mungry.com
Legal / privacy: legal@mungry.com
General inquiries: inquiries@mungry.com
Mungry LLC
784 S. Clearwater Loop, STE B
Post Falls, ID 83854, USA
(208) 379-5210