Workspace / App
Browser requests enter the MIAO API, which rechecks the user, workspace membership, app permissions and field authorization. Knowing a URL grants no data access.
Implemented in codeSELF-HOSTING · SECURITY BOUNDARIES
MIAO runs as one Go process with PocketBase, UI and migrations embedded. One server-side API handles identity, permissions, Agents and background jobs. This page describes only capabilities documented in the source and operations guide.
Implemented in codeNeeds real-environment verificationNot provided: multi-node HA, cloud SLA, SOC compliance
PM2 only manages the process; the reverse proxy owns public HTTPS, domain and port boundaries. Raw PocketBase admin interfaces, file tokens and backup APIs are not exposed publicly.
curl and openssl, then get the release package from GitHub Releases.Browser requests enter the MIAO API, which rechecks the user, workspace membership, app permissions and field authorization. Knowing a URL grants no data access.
Implemented in codeAgents and background jobs use server-side authorization context, budgets and run receipts; they do not retain browser login tokens for long-running work. Real model accounts and long-running execution still require field verification.
Needs real-environment verificationPublic pages return only explicitly authorized record fields and images. They do not expose a workspace or bypass the app publication scope.
Implemented in codeThe production domain, real mail, AI Gateway, Jev, backup and restore, and reverse proxy all require target-environment verification. This page does not promise multi-node HA, cloud SLA, certification or paid inference quotas.