Trust
Security at MAMA
How MAMA approaches uploads, egress, auth, and infrastructure hardening.
In the product
Server-side upload allowlists (magic bytes / MIME / path), CSP on landing surfaces, MFA gates for admin, and host-role separation (Render UI+Slack vs ECS API-only).
Roadmap controls
AWS GuardDuty Malware Protection for S3 on receipt/object buckets, continued Dependabot floors, and documented risks in the security register.
- Least-privilege host roles
- No auth secrets in localStorage
- Quarantine path for malicious objects (planned)