Security is infrastructure. Here's exactly how we protect your data, your API credentials, and the applications you build on top of us.
SOC 2 Type I audit is targeted after our seed round, with Type II to follow. Controls are mapped to AICPA Trust Services Criteria today. Report available to enterprise customers under NDA once issued.
We comply with GDPR requirements for EU data subjects — lawful bases, data subject rights, DPAs, and cross-border transfer mechanisms (SCCs).
California Consumer Privacy Act compliance — we honor data deletion, opt-out, and disclosure rights for California residents.
All API traffic and web sessions are encrypted in transit using TLS 1.3. Older protocol versions are rejected at the edge.
Do you train AI models on my data?
No. Customer Data sent through the API is processed transiently to service your request and is never used to train our models. See our Privacy Policy for details.
Can I get a Data Processing Agreement (DPA)?
Yes. Enterprise and Builder plan customers can request a signed DPA at legal@marketmindai.cloud. See our DPA summary for the full framework, and note we use standard SCCs for cross-border transfers.
Where is my data stored?
By default, data is processed and stored in the United States. EU data residency is available for Enterprise customers — contact us to discuss your requirements.
How do I report a security vulnerability?
Email security@marketmindai.cloud with a description of the issue. We aim to acknowledge all reports within 48 hours and provide a fix timeline within 5 business days. We do not pursue legal action against good-faith researchers.
Standardized responses across the three primary CISO risk vectors — data leakage, model training contamination, and infrastructure security.
Is customer data used to train or fine-tune AI models?
No. MarketMind AI operates under a strict zero-model-training policy. Upstream LLM calls are routed through Google Vertex AI enterprise endpoints covered by enterprise data privacy terms (zero prompt retention and zero model training).
How is tenant data isolated in your vector database and backend?
Logical tenant isolation is enforced at the API gateway level. Vector embeddings and memory stores reside in tenant-segregated pgvector database schemas on Cloud SQL, preventing cross-tenant data bleed.
What encryption standards are applied to data at rest and in transit?
All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256 via Google Cloud Key Management Service (KMS).
How are API keys and database credentials managed?
Credentials are never hardcoded. All secrets, API keys, and connection strings are managed, rotated, and injected at runtime via Google Cloud Secret Manager.
What security certifications does your platform maintain?
MarketMind AI is hosted on Google Cloud Platform (GCP) and inherits GCP's underlying compliance certifications, including SOC 1/2/3, ISO/IEC 27001, and PCI-DSS compliance for physical and hypervisor layers.
How is code deployed and audited for vulnerabilities?
Infrastructure changes are managed via version-controlled Terraform scripts. Serverless Cloud Run microservices undergo automated build testing and container vulnerability scanning within CI/CD deployment pipelines.
Who has administrative access to production data?
Access follows the Principle of Least Privilege (PoLP) managed through GCP IAM and Role-Based Access Control (RBAC). Service accounts run with minimal required permissions.
How are administrative activities monitored?
Immutable Cloud Audit Logs track all administrative actions, API calls, and system events, streaming alerts for anomalous access patterns.
Found a security issue? We take all reports seriously. Reach out and we'll respond within 24 hours.
security@marketmindai.cloud →