Security at MindSim

Your most sensitive judgment.Protected at every layer.

MindSim models how people think, decide, and respond. That can include the context an enterprise protects most carefully. Security is built into every identity, workspace, request, model interaction, and release.

SOC 2compliantHIPAAcompliantGDPRcompliant
Protection activeEvery request verified
MindSimProtected workspace

Identity verifiedVerify identity

Verified

Boundary establishedEstablish boundary

Verified

Action authorizedAuthorize action

Verified

Outcome recordedRecord outcome

Verified
See how protection follows the data

The standard

Security should feel invisible to your team.And remain inspectable to yours.

People should be able to use MindSim without carrying the burden of its controls. Security, risk, privacy, and compliance teams should be able to see exactly what protects the system.

01

Control who can enter.

Enterprise identity, MFA, revocable sessions, and role-based access keep authorization deliberate.

02

Keep every workspace separate.

Tenant context is established on the server and enforced across data, files, AI processing, and administration.

03

Know what happened.

Important activity creates reviewable evidence while sensitive content stays out of routine operational telemetry.

The request path

One boundary.Checked four times.

Security is not a single gate at sign-in. Every consequential request moves through identity, tenant isolation, authorization, and evidence.

Boundary established

Resolve the workspace on the server.

Every request is scoped to one workspace. Membership is checked server-side, routing context is never trusted from the browser, and ambiguity fails closed.

Automated isolation tests block cross-workspace regressions.
Workspace-scoped AI boundary
Your MindSimBuilt from your workspace
No shared model training
No cross-workspace learning
Raw prompts excluded from telemetry
Authorized resultReturned to this workspace only

AI data protection

Your data builds your MindSim.It does not train shared foundation models.

The value of MindSim comes from person-specific context. That context stays scoped to the workspace that supplied it, including AI derivation, model credentials, retrieval, and results.

  • Workspace-scoped derivation.One workspace cannot shape another workspace's MindSim.
  • Customer control.Model selection, customer-managed credentials, and regional processing controls are available for enterprise needs.
  • Hardened context boundaries.Untrusted content is treated as data, with prompt-injection defenses around persona and knowledge boundaries.

Control coverage

Protection that reachesfrom sign-in to shipment.

The controls below work as one system. Identity limits the actor, isolation limits the data, encryption limits exposure, evidence supports review, and delivery gates protect every change.

01

Identity and access

The right person. The right role. The right moment.

  • Enterprise SSO and SAML
  • MFA through your identity provider
  • Revocable, server-validated sessions
  • Workspace and administrative RBAC
  • Time-boxed elevated access
02

Data protection

Customer data stays encrypted, scoped, and controlled.

  • TLS for data in transit
  • AES-256 encryption at rest
  • AES-256-GCM for credentials and tokens
  • Time-limited signed file access
  • Recoverable deletion safeguards
03

Integrity and monitoring

Important actions leave evidence. Important changes get checked.

  • Authentication and access event logging
  • Append-only protection for sensitive records
  • Incident tracking and alerting
  • PII-scrubbed operational telemetry
  • Database integrity and abuse controls
04

Secure engineering

Security checks travel with every change.

  • Required test, type, lint, and build gates
  • Governed, forward-only data migrations
  • Dependency and secret scanning
  • Prompt-injection sink checks
  • Reproducible, reviewed releases

Compliance and assurance

Compliance is not a badge.It is a working control system.

MindSim is SOC 2, HIPAA, and GDPR compliant. Each program examines a different part of trust, so the underlying controls are mapped to the objective they support and backed by reviewable evidence.

SOC 2Independent controls assurance
HIPAAHealthcare data safeguards
GDPRPrivacy rights and accountability
Current scope, evidence, and supporting materials are available through the Trust Center and enterprise diligence process.
Control objectiveSOC 2HIPAAGDPR
01Logical access and least privilegeAccess controlsAccess safeguardsSecurity of processing
02Encryption and protected transmissionData protectionTransmission safeguardsSecurity of processing
03Monitoring and incident responseSystem operationsAudit safeguardsIncident readiness
04Secure change managementChange controlsIntegrity safeguardsTechnical measures
05Privacy rights and governanceGovernance evidencePrivacy operationsData subject rights

Secure delivery

Trust is earned once.Then earned again with every release.

Security travels with the software lifecycle, from design through response. Required gates prevent a change from bypassing the controls that protect customers.

01

Design

Threats, tenant boundaries, and access paths are considered before implementation.

02

Verify

Automated isolation, authorization, quality, and security checks test the change.

03

Release

Required gates, governed migrations, and reproducible builds control delivery.

04

Observe

Operational telemetry, audit events, and alerting surface unexpected behavior.

05

Respond

Incidents are acknowledged, investigated, remediated, and tracked to resolution.

Enterprise diligence

Bring your questionnaire.We will bring the evidence.

Security reviews should reduce uncertainty, not create more of it. We support enterprise and financial-institution diligence with clear answers and the materials needed to verify them.

Available for diligence
  • Current attestations and policies
  • Security questionnaire responses
  • Architecture and data-flow review
  • Sub-processor inventory and agreements
  • Detailed control evidence under NDA