Trust

Security at MAMA

How MAMA approaches uploads, egress, auth, and infrastructure hardening.

In the product

Server-side upload allowlists (magic bytes / MIME / path), CSP on landing surfaces, MFA gates for admin, and host-role separation (Render UI+Slack vs ECS API-only).

Roadmap controls

AWS GuardDuty Malware Protection for S3 on receipt/object buckets, continued Dependabot floors, and documented risks in the security register.

  • Least-privilege host roles
  • No auth secrets in localStorage
  • Quarantine path for malicious objects (planned)