When you land on sg-g-msg-api.miolive.app, you get a 403 Forbidden page β a clear sign this is an API endpoint, not a website you visit in a browser. So typical trust signals like contact info, about pages, and privacy policies simply don't apply here. That doesn't mean it's suspicious; it's just a different kind of service.
For an API, the most important factors are security and uptime. This subdomain has a valid SSL certificate and a clean reputation across blacklists and Google's threat databases. However, the server still accepts outdated TLS 1.0 and 1.1 connections, which is a minor technical oversight. Modern APIs should disable those protocols to prevent downgrade attacks.
There's no way to tell who runs this endpoint β WHOIS data is hidden by the .app TLD, and the domain lacks any company branding. That's common for internal or developer-focused APIs, but it means you have to rely on the service it connects to. If you're a developer considering using this API, check the parent domain (miolive.app) for documentation and terms. As a consumer, you probably won't interact with it directly, which makes the safety question less about a scam and more about technical hygiene β and on that front, it's passable but not perfect.