Compliance and privacy

Clear controls. No unearned certification claims.

MindShield documents the controls available today and separates them from formal certifications or assurance work that has not yet been completed.

Controls available today

These capabilities support responsible security operations, but they do not by themselves constitute independent certification.

ControlStatusCurrent boundary
Encryption controlsAvailableAES-256 protection is used within supported backup workflows.
Transport protectionAvailableTLS protects supported communication between components.
Role-based accessAvailableAdministrative permissions are scoped through roles and organization context.
Tenant isolationAvailablePostgreSQL Row-Level Security is part of the tenant-isolation enforcement model.
Audit evidenceAvailableSecurity-sensitive and operational actions are recorded where implemented.
Privacy documentationAvailablePublic privacy, terms and cookie-related information is maintained on the website.

Assurance roadmap

PLANNED

ISO 27001 readiness

Formal information-security management preparation and evidence collection.

PLANNED

SOC 2 readiness

Control definition, operating evidence and independent assessment planning.

PLANNED

ISO 22301 alignment

Business-continuity management practices and documented recovery governance.

Important: MindShield does not currently claim ISO 27001, SOC 2 or ISO 22301 certification. Any future status will be published only after the relevant process is complete.