"It also opens the door to legitimate privacy and security concerns. For Mighty to work, everything you type – every username, password, address, credit card number, SSN, and more – has to be routed through its servers. Every website cookie is saved there too.
Mighty's answer is that its servers and code were audited by a third-party firm in February 2021, and that its infrastructure will be audited each year. Sensitive data is encrypted, it adds, on an isolated virtual machine, and not backed up anywhere else. Automated tools, rather than humans, manage things like browser updates, and the company says it has policies that employees can't view your history. Keystrokes, meanwhile, are encrypted for transmission, and not stored.
There's not, however, HIPAA compliance, or SOC-2. Mighty says "we may look at getting compliance in late 2022." Two-factor authentication is also "coming soon," the startup says."