Corporate Policy

Corporate Information Security Policy

This Information Security Policy (ISP) acts as the operational constitution for MarketMind AI's SOC 2 audit readiness. It translates technical cloud architecture into clear, enforceable company rules required by auditors and enterprise CISOs.

Last updated: August 2026

1. Program Governance & Risk Management

Scope & Applicability

Governs all workforce members, codebases, Google Cloud infrastructure, and third-party API integrations.

Executive Oversight

Designates the Founder/CEO as the ultimate authority responsible for policy maintenance, annual security reviews, and resource allocation.

Annual Risk Assessment

Mandates an annual formal risk assessment evaluating operational, technical, vendor, and product threat vectors.

2. Asset Classification, Confidentiality & AI Governance

Data Classification Scheme

Categorizes data into Public, Internal, and Confidential Customer Data (prompts, vector embeddings, schemas).

Zero Model Training Mandate

Enforces strict legal and technical prohibitions against using customer inputs, outputs, or memory for training public or multi-tenant models.

Tenant Isolation

Mandates schema-level logical separation of customer memory stores on Cloud SQL (pgvector).

Encryption Policy

Requires AES-256 encryption at rest (via GCP KMS) and TLS 1.3 in transit across all internal microservice boundaries.

3. Identity & Access Management (IAM)

Principle of Least Privilege

System permissions are assigned strictly based on job function and enforced via GCP IAM roles.

Multi-Factor Authentication (MFA)

Enforces mandatory MFA across all corporate email, source control, and GCP accounts.

Secrets Management

Strictly prohibits hardcoded API keys or database credentials; all secrets must be dynamically injected via Google Cloud Secret Manager.

Onboarding & Offboarding

Mandates background verification before granting access and same-day automated access revocation upon termination.

4. Software Development & Change Management

Infrastructure as Code (IaC)

100% of production GCP resources must be provisioned and modified using version-controlled Terraform code.

Deployment Guardrails

Requires peer code reviews and automated dry-run checks (terraform plan) prior to production execution.

CI/CD Pipeline Security

Automated vulnerability scanning of container images within Cloud Build/GitHub Actions prior to Cloud Run deployment.

5. System Operations & Incident Response

Continuous Logging

Immutable logging enabled across all environments via GCP Cloud Audit Logs.

Anomaly Detection

Cloud Monitoring alerts configured for unexpected API egress spikes, authorization failures, or budget thresholds.

Incident Management & SLA

Defines formal incident triage steps and mandates notifying impacted enterprise customers within 48 hours of a confirmed breach.

Workstation Protection

Mandates full-disk encryption (FileVault/BitLocker), automatic OS patching, and endpoint protection on all employee hardware.

6. Vendor Management & Data Disposal

Sub-Processor Reviews

Mandatory security evaluation of all third-party vendors (including Google Vertex AI) prior to processing customer payloads.

Data Sanitization SLA

Wipes all tenant vector indexes, database records, and backups within 30 days of contract termination.

Questions about our security policies? Contact us at security@marketmindai.cloud