How We Protect Your Data.
1. Security Practices
MindVault implements industry-standard security controls across our infrastructure and product architecture.
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Access to production systems follows the principle of least privilege with role-based access controls. We conduct regular security assessments and maintain audit logs for all system access.
Our ML models run in isolated server-side environments. The browser SDK transmits only pseudonymized statistical behavioral telemetry. No keystroke content, passwords, screenshots, or message content is collected. Behavioral telemetry and statistical features may constitute personal data when linked to a user or device, and are handled as privacy sensitive security data.
2. Privacy by Architecture
MindVault's behavioral analysis captures interaction patterns (timing, rhythm, navigation sequences) and converts them into pseudonymized statistical profiles in real time. We do not capture keystroke content, passwords, screenshots, or personal communications.
This is privacy by architecture, not policy. The system is designed so that sensitive content is never collected in the first place. By collecting less, there is less to protect. The behavioral telemetry we do collect is minimized, governed, and retained under documented rules.
3. Compliance Alignment
MindVault's architecture is designed to align with the following frameworks:
- SOC 2 Type II — Architecture aligned. Formal audit targeted for 2026.
- ISO 27001 — Controls mapped. Certification timeline aligned with first enterprise deployments.
- GDPR — GDPR: a content blind, data minimized architecture designed to support data protection by design under Article 25.
- CCPA — CCPA: we do not sell or share personal information. Behavioral telemetry is collected only for security purposes.
- HIPAA — No protected health information captured. Architecture supports covered entity requirements.
MindVault is not currently certified under SOC 2 or ISO 27001. We are transparent about this because trust requires honesty about where we are, not where we intend to be.
4. Responsible Disclosure
We welcome responsible security research. If you believe you have discovered a vulnerability in any MindVault system, please report it to: info@mindvaultinc.com.
We are committed to acknowledging receipt within 2 business days, providing an initial assessment within 5 business days, and working collaboratively toward resolution. We will not pursue legal action against researchers who report vulnerabilities in good faith and follow responsible disclosure practices.
Our security.txt file is available at: https://mindvaultinc.com/.well-known/security.txt
5. Infrastructure and Subprocessors
MindVault uses the following third-party services in our infrastructure:
- Netlify — Website hosting, CDN, DNS, and edge-layer DDoS protection
- GoDaddy — Domain registrar
All subprocessors are evaluated for security posture and compliance alignment before integration.
6. Questions
For security inquiries, architecture documentation, or to request our security questionnaire responses, contact info@mindvaultinc.com.
