Security & trust
Built to earn your security team’s yes. Here is exactly how we handle your data.
Menttion runs on encrypted, access-controlled infrastructure, honors GDPR and CCPA, and hands you a DPA on request. No hand-waving, no invented badges — just how it actually works.
[01] How we protect it
/ Controls ↔ Data
Encrypted in transit and at rest
Every connection runs over TLS. Data and integration credentials are encrypted at rest on managed AWS and MongoDB Atlas infrastructure.
Isolated by tenant
Every brand is its own tenant. Reads are scoped to your workspace, so one customer's data can never surface inside another's.
Least-privilege access
Production access is limited to the people who need it, over authenticated channels, and integration tokens are scoped to only the data you connect.
Yours to take back
Export your data whenever you want, and delete a workspace or your whole account to remove it after a short recovery window.
[02] What we store, and where
/ Data ↔ Lifecycle
Wekeepwhattheproductneeds,andnothingwecannotexplain.
Account and workspace details, the engine answers we retrieve for you, product usage, and any integration data you connect. The full breakdown lives in the privacy policy.
- Where it runs
- Amazon Web Services, United States
- Database
- MongoDB Atlas, managed and encrypted at rest
- In transit
- TLS 1.2+ on every connection
- At rest
- Encrypted storage; credentials encrypted per integration
- Retention
- Kept while your account is active
- Deletion
- Removed after a short recovery window on request
[03] Compliance and your rights
/ GDPR ↔ CCPA
Yourrightsarehonoredinfull,whereveryouare.
- Access, correct, export, or delete your data — email us and we action it.
- A Data Processing Agreement (DPA) is available on request for any paying or evaluating customer.
- We don't sell your data, and integration data is used only for the syncs you configure.
On certifications, plainly
Menttion is not yet SOC 2 or ISO 27001 certified. We would rather tell you that than imply a badge we have not earned. A formal compliance program is on our roadmap, and this page will be updated the moment that changes.
If your procurement needs a security questionnaire completed in the meantime, send it over — we will fill it out.
Request a security review[04] Subprocessors
/ Vendor ↔ Purpose
We rely on a small set of vetted providers, each receiving only what its job requires:
| Subprocessor | Purpose | Data it handles |
|---|---|---|
| Amazon Web Services | Cloud hosting and infrastructure | Application data, hosted in the US |
| MongoDB Atlas | Managed, encrypted database | Workspace and account data |
| Stripe | Payments and subscriptions | Billing details — no card data touches our servers |
| Brevo | Transactional email | Name and email address |
| AI model providers | AI model access for scans and content | Prompts and generated text |
| Answer-engine & search-data providers | Answer-engine and search data | Prompts and public search results |
We post material changes here before they take effect. Want the current list in writing? It travels with the DPA — just ask.
Working with procurement
Need a DPA or a security review?
Email us and tell us what you need — a signed DPA, the subprocessor list, or a completed security questionnaire. We turn these around quickly for evaluating and paying customers.
Found a security issue? Please report it to hi@menttion.com and we will respond promptly.