Certifications & Compliance
SOC 2 Type II
Annual third-party audit of security, availability, and confidentiality controls.
GDPR Compliant
Full compliance with EU General Data Protection Regulation.
HIPAA Ready
HIPAA-compliant deployment available for healthcare enterprise customers.
ISO 27001
ISO 27001 certification in progress, expected Q4 2026.
PCI DSS
PCI-compliant infrastructure for payment data handling.
Security Architecture
TLS 1.3 Encryption
All data in transit is encrypted with TLS 1.3. We do not support deprecated TLS versions.
AES-256 at Rest
All stored data is encrypted with AES-256 using hardware security modules (HSM).
Private VPC
Enterprise deployments can be isolated in dedicated VPCs with no shared infrastructure.
API Key Security
Signed JWT tokens, IP allowlisting, key rotation, and scoped permissions for API access.
Audit Logs
Immutable audit logs for all API calls, admin actions, and data access on enterprise plans.
RBAC
Role-Based Access Control with fine-grained permissions for team and enterprise accounts.
DDoS Protection
Cloudflare-backed DDoS protection and rate limiting at the edge.
Penetration Testing
Quarterly third-party penetration testing by independent security firms.
Responsible Disclosure
If you discover a security vulnerability in Mentneo's systems, please report it responsibly to our security team. We commit to acknowledging reports within 24 hours, investigating all credible reports, and rewarding significant findings through our bug bounty program.