CISO Briefing Sheet

Enterprise Security & Architecture Overview

Designed for enterprise InfoSec and CISO procurement reviews, MarketMind AI is a tenant-isolated, multi-agent orchestration platform engineered on an AWS / GCP hybrid multi-cloud architecture with an absolute Zero Model Training mandate.

Last updated: August 2026

1. Architectural Topology & Infrastructure

Serverless Compute

Workloads execute within containerized serverless microservices across Google Cloud Run and AWS Lambda (US-East) inside private Virtual Private Clouds (VPCs) with zero public interface exposure.

Vector & Data Memory

Managed Cloud SQL utilizing pgvector for vector similarity search, logically partitioned at the database schema level to guarantee multi-tenant data isolation.

API Gateway & Governance

LiteLLM Proxy manages rate limits, cost tracking, and secure egress to foundational models via enterprise-tier Google Vertex AI endpoints.

Infrastructure as Code (IaC)

100% of cloud resources are provisioned, version-controlled, and audited using modular Terraform scripts.

2. Data Privacy & AI Model Safeguards

Zero Model Training Guarantee

Customer inputs, prompts, vector embeddings, and outputs are contractually and technically excluded from training, fine-tuning, or aligning public or multi-tenant models.

Zero Data Retention Policy

Model inference calls operate over enterprise Vertex AI APIs under strict zero-prompt-retention terms.

Data Lifecycle & Destruction

Upon subscription termination or written request, all tenant vector stores, database schemas, and backups are permanently purged within 30 days.

3. Encryption, Identity & Secrets Management

Encryption Standards

Full TLS 1.3 encryption in transit across all microservices and API gateways; AES-256 encryption at rest managed through Google Cloud Key Management Service (KMS).

Credential Protection

Secrets, database connection strings, and model credentials are store-encrypted and injected dynamically at runtime via Google Cloud Secret Manager.

Identity & Access

Principle of Least Privilege (PoLP) enforced through GCP Identity & Access Management (IAM) and Role-Based Access Control (RBAC).

4. Monitoring & Compliance Framework

Immutable Audit Logging

All administrative actions, code deployments, and API system events are recorded via Cloud Audit Logs for continuous security monitoring.

Inherited Certifications

Built on AWS / GCP hybrid infrastructure adhering to SOC 1/2/3, ISO/IEC 27001, and PCI-DSS security frameworks. GCP is HIPAA BAA-eligible; MarketMind AI is not currently HIPAA-compliant — PHI processing requires an executed BAA (see AUP).

Questions for our security team? Contact us at security@marketmindai.cloud