This Information Security Policy (ISP) acts as the operational constitution for MarketMind AI's SOC 2 audit readiness. It translates technical cloud architecture into clear, enforceable company rules required by auditors and enterprise CISOs.
Last updated: August 2026
Governs all workforce members, codebases, Google Cloud infrastructure, and third-party API integrations.
Designates the Founder/CEO as the ultimate authority responsible for policy maintenance, annual security reviews, and resource allocation.
Mandates an annual formal risk assessment evaluating operational, technical, vendor, and product threat vectors.
Categorizes data into Public, Internal, and Confidential Customer Data (prompts, vector embeddings, schemas).
Enforces strict legal and technical prohibitions against using customer inputs, outputs, or memory for training public or multi-tenant models.
Mandates schema-level logical separation of customer memory stores on Cloud SQL (pgvector).
Requires AES-256 encryption at rest (via GCP KMS) and TLS 1.3 in transit across all internal microservice boundaries.
System permissions are assigned strictly based on job function and enforced via GCP IAM roles.
Enforces mandatory MFA across all corporate email, source control, and GCP accounts.
Strictly prohibits hardcoded API keys or database credentials; all secrets must be dynamically injected via Google Cloud Secret Manager.
Mandates background verification before granting access and same-day automated access revocation upon termination.
100% of production GCP resources must be provisioned and modified using version-controlled Terraform code.
Requires peer code reviews and automated dry-run checks (terraform plan) prior to production execution.
Automated vulnerability scanning of container images within Cloud Build/GitHub Actions prior to Cloud Run deployment.
Immutable logging enabled across all environments via GCP Cloud Audit Logs.
Cloud Monitoring alerts configured for unexpected API egress spikes, authorization failures, or budget thresholds.
Defines formal incident triage steps and mandates notifying impacted enterprise customers within 48 hours of a confirmed breach.
Mandates full-disk encryption (FileVault/BitLocker), automatic OS patching, and endpoint protection on all employee hardware.
Mandatory security evaluation of all third-party vendors (including Google Vertex AI) prior to processing customer payloads.
Wipes all tenant vector indexes, database records, and backups within 30 days of contract termination.
Questions about our security policies? Contact us at security@marketmindai.cloud