Security You Can Trust

Enterprise-grade security is not optional at Mentneo. Every layer of our infrastructure is designed, audited, and continuously monitored to protect your data.

Certifications & Compliance

Certified

SOC 2 Type II

Annual third-party audit of security, availability, and confidentiality controls.

Certified

GDPR Compliant

Full compliance with EU General Data Protection Regulation.

Available

HIPAA Ready

HIPAA-compliant deployment available for healthcare enterprise customers.

In Progress

ISO 27001

ISO 27001 certification in progress, expected Q4 2026.

Available

PCI DSS

PCI-compliant infrastructure for payment data handling.

Security Architecture

TLS 1.3 Encryption

All data in transit is encrypted with TLS 1.3. We do not support deprecated TLS versions.

AES-256 at Rest

All stored data is encrypted with AES-256 using hardware security modules (HSM).

Private VPC

Enterprise deployments can be isolated in dedicated VPCs with no shared infrastructure.

API Key Security

Signed JWT tokens, IP allowlisting, key rotation, and scoped permissions for API access.

Audit Logs

Immutable audit logs for all API calls, admin actions, and data access on enterprise plans.

RBAC

Role-Based Access Control with fine-grained permissions for team and enterprise accounts.

DDoS Protection

Cloudflare-backed DDoS protection and rate limiting at the edge.

Penetration Testing

Quarterly third-party penetration testing by independent security firms.

Responsible Disclosure

If you discover a security vulnerability in Mentneo's systems, please report it responsibly to our security team. We commit to acknowledging reports within 24 hours, investigating all credible reports, and rewarding significant findings through our bug bounty program.

Report VulnerabilitySecurity Contact