Security Overview
MioCC is an offline-first privacy application designed to protect text and files directly on the user's device.
Its core protection and restoration workflows do not require original content, passwords, PINs, private keys or decrypted data to be sent to the MioCC owner for encryption or decryption.
MioCC is designed to reduce unnecessary exposure of sensitive content. It does not claim to provide absolute security, protect a compromised device or eliminate risks created by weak passwords, malicious software, operating-system vulnerabilities or unsafe user behavior.
This page describes the current security model and protection boundaries documented for MioCC.
MioCC for Android and MioCC for Windows follow the same security principles but are developed, tested and released independently.
Applies to MioCC 1.0.x. Last updated: July 2026.
Clear security boundaries before technical detail.
This summary explains the security posture without claiming more than the product is designed to provide.
Text and files are handled on the user's device during the core protection workflow.
The core lock and unlock operations are designed as local workflows.
MioCC cannot recover forgotten passwords or passphrases.
Cloud upload is not required for core encryption or decryption.
Captured photos and videos remain inside the MioCC workflow until the user chooses an action.
Saving and sharing happen only through user action and platform workflows.
Reports summarize operations without storing passwords, keys or original file contents.
Controls help leave or reduce the active protected working view where supported.
License verification is separate from protected text and files.
No software can guarantee protection against every device, user or operating-system risk.
Offline-First Processing
MioCC is built around a simple security principle: protected content should be handled locally whenever the core product workflow allows it. The lock and unlock process is designed to run on the user's Android or Windows device, without requiring original content or passphrases to be uploaded for encryption or decryption.
Internet access may still be required for activities outside the core protection workflow, such as downloading the product, payment, license verification, updates or public documentation.
What MioCC Does Not Send
For the core protection and restoration workflow, MioCC is designed not to send the following to the MioCC owner for encryption or decryption:
- Original plaintext text entered by the user.
- Original file contents selected for protection.
- Passwords, passphrases or PINs used to lock or unlock content.
- Private keys or raw decrypted data produced by an unlock operation.
Password and Key Responsibility
MioCC does not provide a password recovery path. The password or passphrase used to protect content is the user's responsibility.
- Use a strong passphrase. Weak or reused passwords reduce the protection provided by encryption.
- Keep the passphrase separate. Do not send the password together with the protected file or protected text.
- Store it safely. If the password is lost, MioCC, the owner, the seller or any third party cannot recover the original content.
Text and File Protection
MioCC protects text and files through local cryptographic workflows. Product reports currently identify AES-256-GCM, PBKDF2-SHA256 and 300,000 iterations as the reported cryptographic configuration, with protected formats such as MIOCC-TEXT-V1 and MIOCC-FILE-V3.
Salt and nonce/IV values are security-critical values used by the protection format. They should be generated by the application workflow and must not be treated as passwords or recovery secrets by users.
Exact cryptographic behavior should be verified against the final release code before this document is considered a final technical reference.
Capture → Protect → Share
On Android, MioCC may allow users to capture photos or videos directly inside the application workflow. Captured media is not automatically added to the phone gallery. The user can review it, protect it, remove it, save it or share the protected result. The protected result can then be stored locally or shared through the user's preferred communication channel.
Create a photo or video inside MioCC.
Lock the captured content before normal sharing.
Send or store the protected result by user choice.
Receive → Unlock → View
Protected MioCC files or protected text may be received through email, messaging apps, cloud storage, USB drives or other transfer methods. The user attaches the protected file or pastes protected text, enters the correct password and presses UNLOCK. The restored content remains under the user's control according to the selected platform workflow.
Obtain protected content from any normal transfer method.
Use MioCC and the correct password to restore content.
Review restored content inside the app where supported.
Temporary In-App Media Workflow
MioCC's Android media workflow is designed so captured or restored media can be reviewed inside the current app session where supported. This can reduce the need to immediately open restored images or videos in another application.
This should not be described as a forensic guarantee. Device operating systems may use memory, temporary storage, thumbnails, media decoders or caches according to platform behavior. The safe public claim is that MioCC does not automatically add captured media to the phone gallery and that the user controls whether to save, share, protect or remove it.
Saving and Sharing
Saving and sharing are user-initiated actions. On Android, sharing may use the native Android Share sheet. On Windows, output is organized locally through MioCC folders and platform file handling.
Users should share protected files and passwords through separate channels where possible. Sending the protected file and the password together reduces security.
Security Reports
MioCC can generate local security reports that summarize what was processed and whether the operation completed successfully. Reports are intended for transparency and user confidence.
operation type, edition, platform, number of processed files, input and output sizes, timing, status and session identifier.
passwords, PINs, plaintext messages, file contents, encryption keys, salt values, IV/nonce values or raw encrypted payload.
Session Cleanup, Panic and Exit Controls
MioCC includes workflow controls such as Start Over, Lock App, Exit and Panic. These controls are intended to help the user leave, reset or reduce the currently visible protected working view.
- Start Over starts a new working flow and helps clear the current result view according to the active platform workflow.
- Lock App returns the user toward the password/start state and helps reduce current session visibility.
- Panic is a fast privacy control for leaving or closing the active protected view where supported.
- Exit leaves the current screen or workflow according to the application state.
Licensing and Device Information
License verification may use device-related information or a license file, depending on platform and edition. Licensing data is separate from protected content and is not used to decrypt user files.
Payment, activation and licensing behavior should be read together with the Privacy Policy, Terms of Use, End User License Agreement and Payment, Activation & Refund Policy.
Threat Model
Can Reduce
- Unnecessary cloud exposure by keeping core protection and restoration local.
- Accidental sharing of original content by encouraging protection before sharing.
- Unclear processing history through local security reports.
- Gallery exposure of captured media by not automatically adding captured photos or videos to the phone gallery.
- Casual on-screen exposure through session controls such as Lock App and Panic.
Cannot Prevent
- Compromised devices. Malware, spyware, keyloggers or rooted/jailbroken systems may undermine security.
- Weak passwords. Short, reused or guessable passphrases can reduce protection.
- User mistakes. Sending the password with the protected file or saving unprotected content elsewhere can defeat the workflow.
- Operating-system vulnerabilities. MioCC cannot guarantee protection against every Android, Windows or hardware-level issue.
- Third-party app behavior. Messaging apps, cloud apps or viewers may have their own storage, preview or cache behavior.
User Security Responsibilities
- Choose strong and unique passwords or passphrases.
- Keep passwords separate from protected files.
- Keep the device, operating system and security updates current.
- Avoid using MioCC on compromised, rooted, jailbroken or untrusted devices.
- Review output files and reports before sharing sensitive content.
- Understand edition and platform limits before relying on MioCC for important workflows.
Security Limitations
MioCC is not a substitute for full-device security, secure backups, enterprise device management, legal compliance programs or professional incident response. It is a privacy application designed to reduce unnecessary exposure of text and files through offline-first protection workflows.
Android and Windows may not behave identically. File handling, preview behavior, sharing paths, supported media preview and storage locations can differ by platform and version.
Reporting a Security Issue
Security concerns, suspected vulnerabilities or documentation corrections may be reported by email.
For your own security, never send passwords, PINs, cryptographic keys or unprotected confidential content by email.