Security & Trust

Built to be trusted.

Security is infrastructure. Here's exactly how we protect your data, your API credentials, and the applications you build on top of us.

Compliance & Certifications

SOC 2 Type IPlanned

SOC 2 Type I audit is targeted after our seed round, with Type II to follow. Controls are mapped to AICPA Trust Services Criteria today. Report available to enterprise customers under NDA once issued.

GDPR CompliantActive

We comply with GDPR requirements for EU data subjects — lawful bases, data subject rights, DPAs, and cross-border transfer mechanisms (SCCs).

CCPA CompliantActive

California Consumer Privacy Act compliance — we honor data deletion, opt-out, and disclosure rights for California residents.

TLS 1.3 EverywhereActive

All API traffic and web sessions are encrypted in transit using TLS 1.3. Older protocol versions are rejected at the edge.

Security Practices

Infrastructure & Data Residency

  • ✓Hosted on enterprise-grade cloud infrastructure (US-East primary, US-West failover).
  • ✓All data at rest encrypted using AES-256.
  • ✓Customer Data processed in the US by default. EU data residency available for enterprise customers.
  • ✓Daily encrypted backups with 30-day retention. Point-in-time recovery available.

Access Controls

  • ✓Role-based access control (RBAC) across all internal systems.
  • ✓Multi-factor authentication (MFA) enforced for all MarketMind staff accounts.
  • ✓Principle of least privilege — engineers access only what their role requires.
  • ✓All privileged access logged and reviewed quarterly.

Monitoring & Threat Detection

  • ✓24/7 automated anomaly detection on API traffic and authentication events.
  • ✓Distributed denial-of-service (DDoS) mitigation at the edge via Cloudflare.
  • ✓Real-time alerting on suspicious access patterns, rate-limit abuse, and credential stuffing.
  • ✓Security incident response plan with defined escalation paths and <2h triage SLA.

Vulnerability Management

  • ✓Dependency scanning on every code merge to detect known CVEs.
  • ✓Periodic penetration testing by external security researchers.
  • ✓Responsible disclosure program — see below to report a vulnerability.
  • ✓Critical patches deployed within 24 hours of confirmed severity.

Incident Response

  • ✓Defined severity tiers (P0–P3) with escalation and communication procedures.
  • ✓Affected customers notified within 48 hours of a confirmed data breach. Regulatory authorities notified within 72 hours per GDPR Article 33.
  • ✓Post-mortems published for significant platform incidents on our status page.
  • ✓Status page at status.marketmindai.cloud updated in real time during incidents.

Common Questions

Do you train AI models on my data?

No. Customer Data sent through the API is processed transiently to service your request and is never used to train our models. See our Privacy Policy for details.

Can I get a Data Processing Agreement (DPA)?

Yes. Enterprise and Builder plan customers can request a signed DPA at legal@marketmindai.cloud. See our DPA summary for the full framework, and note we use standard SCCs for cross-border transfers.

Where is my data stored?

By default, data is processed and stored in the United States. EU data residency is available for Enterprise customers — contact us to discuss your requirements.

How do I report a security vulnerability?

Email security@marketmindai.cloud with a description of the issue. We aim to acknowledge all reports within 48 hours and provide a fix timeline within 5 business days. We do not pursue legal action against good-faith researchers.

Vendor Security Questionnaire

Standardized responses across the three primary CISO risk vectors — data leakage, model training contamination, and infrastructure security.

1. Data Privacy & AI Model Governance

Is customer data used to train or fine-tune AI models?

No. MarketMind AI operates under a strict zero-model-training policy. Upstream LLM calls are routed through Google Vertex AI enterprise endpoints covered by enterprise data privacy terms (zero prompt retention and zero model training).

How is tenant data isolated in your vector database and backend?

Logical tenant isolation is enforced at the API gateway level. Vector embeddings and memory stores reside in tenant-segregated pgvector database schemas on Cloud SQL, preventing cross-tenant data bleed.

2. Encryption & Key Management

What encryption standards are applied to data at rest and in transit?

All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 via Google Cloud Key Management Service (KMS).

How are API keys and database credentials managed?

Credentials are never hardcoded. All secrets, API keys, and connection strings are managed, rotated, and injected at runtime via Google Cloud Secret Manager.

3. Compliance & Infrastructure Security

What security certifications does your platform maintain?

MarketMind AI is hosted on Google Cloud Platform (GCP) and inherits GCP's underlying compliance certifications, including SOC 1/2/3, ISO/IEC 27001, and PCI-DSS compliance for physical and hypervisor layers.

How is code deployed and audited for vulnerabilities?

Infrastructure changes are managed via version-controlled Terraform scripts. Serverless Cloud Run microservices undergo automated build testing and container vulnerability scanning within CI/CD deployment pipelines.

4. Access Control & Incident Response

Who has administrative access to production data?

Access follows the Principle of Least Privilege (PoLP) managed through GCP IAM and Role-Based Access Control (RBAC). Service accounts run with minimal required permissions.

How are administrative activities monitored?

Immutable Cloud Audit Logs track all administrative actions, API calls, and system events, streaming alerts for anomalous access patterns.

Report a Vulnerability

Found a security issue? We take all reports seriously. Reach out and we'll respond within 24 hours.

security@marketmindai.cloud →