Private Beta security overview

Security & Data Protection

Security built on practical engineering and real-world recovery experience.

MindShield Backup Platform uses layered controls to protect business-critical backup data throughout its lifecycle. Encryption, authenticated communication, role-based authorization, tenant isolation and infrastructure boundaries work together to reduce operational risk while supporting reliable recovery.

Transparent by designThis page documents controls currently available in the Private Beta. Planned capabilities are clearly identified.
AES-256 encryptionTLS communicationRole-based accessTenant isolationLeast privilege
Why security matters to us

Built by people who have seen what happens when protection fails.

22+ yearsof practical data recovery experience

MindShield was created by the engineers behind Mind Merge Data Recovery Services. For more than two decades, our work has involved helping organizations recover after storage failures, ransomware attacks, damaged databases, RAID incidents and unsuccessful recovery attempts.

Engineering principle

A backup is valuable only when it remains secure, accessible and recoverable.

Our security philosophy

Security is more than encryption.

Protecting critical data requires multiple independent controls. MindShield follows a defense-in-depth approach where identity, authentication, authorization, encryption, infrastructure security and recoverability reinforce one another.

“A backup is only valuable when it remains secure, accessible and recoverable.”

Security by design

Layered controls across the platform.

No single feature is treated as the entire security boundary. Protection is distributed across data, identity, transport, authorization and infrastructure layers.

01Encryption

AES-256 backup encryption

Backup archives are encrypted before storage to help protect sensitive business information.

02Transport

TLS-protected communications

Communication between the Windows Agent, Cloud API and Dashboard is protected through HTTPS.

03Identity

Token-based Agent authentication

Each deployed Agent authenticates with the platform before configuration or operational requests are accepted.

04Authorization

Role-based access control

Administrative access is governed through role and organization-aware permissions for multi-organization environments.

05Isolation

PostgreSQL Row-Level Security

Hierarchical authorization is reinforced at the database layer to help isolate tenant-scoped records.

06Infrastructure

Secure production boundaries

Public services operate on Linux infrastructure behind Nginx with HTTPS enforced across external endpoints.

Data protection workflow

Protection from database to encrypted storage.

The current Private Beta focuses on controlled Microsoft SQL Server backup workflows using compression, AES-256 encryption and administrator-configured local storage.

Roadmap boundary: cloud replication and immutable storage are in active development and are not yet available.

  1. 01
    Microsoft SQL ServerProtected workload
  2. 02
    Backup createdScheduled or manual
  3. 03
    CompressedStorage-efficient archive
  4. 04
    AES-256 encryptedProtected before storage
  5. 05
    Stored locallyAdministrator-configured destination
  6. 06
    Cloud replicationIn active development

Multi-tenant security

Organization isolation is reinforced at multiple layers.

MindShield was designed for multi-organization environments. Access decisions combine organization hierarchy, role-based permissions and database-level enforcement to help ensure users can reach only authorized organizations and resources.

Application

Organization-aware authorization

Requests are evaluated using user identity, membership, role and effective organization scope.

Database

PostgreSQL Row-Level Security

Tenant-scoped records are protected through database policies as a defense-in-depth boundary.

Service identity

Least-privilege database access

The application uses a non-superuser database identity without PostgreSQL BYPASSRLS privileges.

Platform security

Clear responsibilities across every platform component.

Each platform layer has a defined role and is separated from the public marketing website.

01

Windows Agent

  • Runs as a Windows Service
  • Token-authenticated operations
  • HTTPS communication
  • No general-purpose remote command execution
02

Cloud API

  • HTTPS enforced
  • Authenticated requests
  • Centralized authorization
  • Tenant-aware request validation
03

Database

  • Non-superuser application identity
  • PostgreSQL Row-Level Security
  • Hierarchical tenant isolation
  • Controlled database execution
04

Dashboard

  • Role-based permissions
  • Organization-aware access
  • Authenticated administrative sessions
  • Separated from the public website

Security principles

The standards behind our engineering decisions.

01

Least privilege

Users and services receive only the permissions required for their defined responsibilities.

02

Encryption by default

Sensitive backup data is encrypted before storage and protected while transmitted between platform components.

03

Tenant isolation

Organizations remain logically separated through layered application authorization and database controls.

04

Recoverability first

Security decisions should strengthen the ability to recover critical business data—not obstruct it.

05

Transparent engineering

Implemented capabilities are documented accurately and clearly separated from planned enhancements.

Security lifecycle

Security is a continuous engineering process.

Controls evolve through implementation, review, operational experience, customer feedback and ongoing improvement. The same discipline is applied repeatedly as the platform matures.

  1. 01Design
  2. 02Implement
  3. 03Review
  4. 04Improve
  5. 05Repeat

In active development

Security roadmap

These capabilities are planned for future releases and are not presented as currently available functionality.

01Multi-Factor Authentication (MFA)
02Cloud replication
03Immutable backup storage
04Advanced audit logging
05Independent security assessment
06Expanded compliance reporting
Responsible disclosure

Report security concerns privately.

We welcome good-faith vulnerability reports that help protect customers, partners and the platform. Reports are reviewed confidentially and investigated promptly.

Email security@mindshieldpk.com

Include in your report

  • Affected URL, host, component or version
  • Clear reproduction steps and potential impact
  • Relevant screenshots or logs with secrets removed
  • Your preferred contact details

Do not send passwords, encryption keys, customer data or backup archives by email.

Frequently asked questions

Direct answers to common security questions.

Is customer backup data encrypted?

Yes. Backup archives are encrypted using AES-256 before they are written to configured storage.

How does MindShield separate organizations?

The platform uses hierarchical organization-aware authorization reinforced by PostgreSQL Row-Level Security for tenant-scoped records.

Can the Windows Agent execute arbitrary remote commands?

No. The Agent is designed for controlled backup-related operations and does not expose a general-purpose remote execution capability.

Is cloud storage available today?

Not in the current Private Beta. The present release uses administrator-configured local storage. Cloud replication is in active development.

Does MindShield currently support MFA?

Not yet. Multi-Factor Authentication is listed as an active security roadmap item and is not represented as an implemented feature.

Has MindShield completed an independent security certification?

Not yet. Independent assessment is planned, and certifications or audit claims will only be published after completion and evidence review.

Engineering commitment

Trust is earned through accurate communication and continuous improvement.

As MindShield evolves, this page will be updated to reflect implemented security controls and clearly distinguish them from future enhancements.

Built by people who have spent more than two decades recovering data after failures. That experience continues to shape every engineering decision behind MindShield.