Security policy

Last revised: 25 September 2026.

1. Scope and responsibility

This policy sets the security baseline for Mindtro’s services. The contracting entity, deployment model and agreed security schedule determine the controls delivered for a particular service. Customer-managed installations also depend on the customer’s infrastructure and configuration. This page is not a claim that every listed control has been independently audited on every product.

2. ISO 27001 scope

MİNDTRO TEKNOLOJİ ANONİM ŞİRKETİ holds ISO 27001 certification, as confirmed by company management. The certification belongs to the Turkish legal entity. It is not presented as certification of Mindtro GmbH, all Mindtro products or a customer’s deployment. Certification scope, covered locations, certificate number, issuing body and validity must be checked against the certificate for any assurance decision. Request the applicable certificate and scope from legal@mindtro.com.

Other certifications or attestations apply only where explicitly evidenced for the relevant entity and service. AWS or Google certifications remain those of the relevant provider and scope; using their services does not certify Mindtro.

3. Access, confidentiality and separation

Our baseline requires named access, least privilege, separation of customer environments and prompt removal of obsolete permissions. Privileged and remote access must use appropriate additional authentication. Staff and service providers with access must be subject to confidentiality duties. Access and changes affecting security must be traceable without unnecessarily copying customer secrets into logs.

4. Data protection and software changes

Deployment security schedules must identify transport protection, encryption and key management, credential handling, patching, dependency review, backup protection and restoration procedures. Secrets must not be committed to source code or exposed to browser clients. Changes affecting these safeguards require review. Vulnerability handling is risk-based; this page does not assert a fixed penetration-test frequency, test certification or universal cipher configuration that has not been evidenced.

AWS and Google are used as service providers. The chosen products, regions and support access must be recorded for each deployment. EU hosting alone does not establish that no third-country access occurs. Consult the DPA and provider overview.

5. Availability, backups and incidents

Backup retention, recovery objectives, tested restoration steps, monitoring coverage and support hours belong in the service-specific schedule. No universal uptime, zero-data-loss promise or 24/7 staffed response is created here.

Where we act as a processor, we notify the customer without undue delay after becoming aware of a personal-data breach and provide available facts and updates. Where we act as controller, we assess the applicable authority and individual notification duties. The GDPR’s authority-notification deadline is not a blanket promise to wait 72 hours before telling a customer.

6. Report a security concern

Email legal@mindtro.com with the affected product, a minimal reproducible description and a safe reply address. Do not include customer secrets or exploit data beyond what is necessary. Agree a secure channel for sensitive evidence. Authorisation is required before intrusive testing; reporting a suspected vulnerability does not grant permission to access another customer’s data.

7. Procurement evidence

Ask for the controls and evidence relevant to your intended deployment. We distinguish policy requirements, implemented controls and independent certification. Security obligations agreed in a signed order or DPA remain binding and are not reduced by this explanatory page.

Questions, notices and requests: legal@mindtro.com. General enquiries: info@mindtro.com, +49 30 166381616.

← Legal documents
Security policy | Mindtro | Intelligence, Engineered