Documentation

MioCC Security Overview

The current protection model, verified cryptographic configuration and practical security boundaries.

Last updated: 23 August 2026English is authoritative

1. Offline-First Processing

MioCC performs core encryption and decryption locally on the user's device. Original content, decrypted content and passwords are not sent to the MioCC developer merely to perform those operations. Download, licensing, updates, support and user-selected third-party sharing may require Internet access.

2. Verified Cryptographic Configuration

  • AES-256-GCM authenticated encryption;
  • PBKDF2-HMAC-SHA-256 password-based key derivation;
  • 300,000 PBKDF2 iterations;
  • a fresh cryptographically random salt for each protected item or operation according to the protected format;
  • a fresh random IV/nonce according to AES-GCM requirements.

Salt and IV/nonce values are not passwords and do not need to be secret. Their required uniqueness and randomness are handled by the application workflow.

3. Password Entry, PASTE and Generation

A password may be entered manually, inserted with PASTE from the operating-system clipboard, or generated locally. PASTE inserts the exact clipboard text without trimming or normalization, keeps the password hidden and does not start processing. The generator does not upload or synchronize the generated value. The strength meter is advisory: it identifies obvious weakness but cannot prove that a password is secure against every threat.

PASTE and COPY use the operating-system clipboard. SHOW PASSWORD reveals the current value on screen. The operating system, keyboard software or other installed applications may have access to clipboard or displayed content depending on the device. Verify the source of pasted data and clear or replace clipboard content after use where supported.

4. Password Responsibility and Recovery

  • save the password securely before encryption;
  • use a strong unique password;
  • send the password separately from the encrypted content where appropriate;
  • do not expect MioCC, the developer, Paddle or Google Play to recover a lost password.

MioCC does not provide a cloud password vault, cross-device password synchronization, password reset or developer-assisted recovery.

5. Local Content and Temporary Processing

Text, files, captures, restored content, temporary working data and reports are handled according to the selected local workflow. Operating systems may use memory, temporary storage, thumbnails, decoders or caches. MioCC does not claim forensic secure erasure or protection of a compromised device.

6. Saving and Sharing

Saving and sharing are user-initiated. Android may use the native Share sheet and system file picker. Sending a protected file and its password through the same channel reduces practical security.

7. Reports

FREE has no operation report. LIGHT provides a Basic report and PRO provides an Advanced report. Reports are designed not to contain passwords, PINs, plaintext content, file contents, encryption keys, salt values, IV/nonce values or raw protected payload.

8. Session Controls

Start Over, Exit, Back and Panic leave, reset or reduce the currently visible working state according to the active screen. Panic closes the active protected view and clears supported temporary session or on-screen data. These controls do not delete files already saved to local storage and are not a secure-erase feature.

9. Licensing Separation

Licensing may use a license identifier, edition, status, activation information and a device or installation identifier. Licensing data is separate from protected user content and is not used to decrypt files.

10. Threats MioCC Cannot Eliminate

  • malware, spyware, keyloggers, rooted or otherwise compromised devices;
  • weak, reused, exposed or lost passwords;
  • operating-system, hardware or third-party application vulnerabilities;
  • unsafe backups, screenshots, clipboard use or sharing choices;
  • physical access to an unlocked device;
  • future cryptanalytic or computing developments.

11. Reporting a Security Issue

Report a suspected security issue to mio.ccomm@gmail.com without including passwords, PINs, private keys or unnecessary unprotected confidential content.