Skip to content

Trust & security

Security and privacy at Myndboosters AI

An agent fleet works inside your systems — your inbox, your repositories, your customer records. This page is the plain description of how that is handled, written to be read by the person whose job is to say no.

  • Encrypted in transit and at rest
  • Your data never trains a model
  • Least-privilege access, revocable by you
  • No badge we cannot evidence

Read this first

What we claim, and what we do not

Myndboosters AI holds no third-party security certification today. There is no SOC 2 report, no ISO 27001 certificate, no CASA assessment and no PCI DSS attestation — which is why you will not find a row of badges on this page. A logo you cannot ask for the report behind is decoration, and we would rather tell you the position than let you infer it.

What follows is a description of how we actually work: what an agent can reach, who else sees the data, what we keep and for how long, and what we will not do with it. Every statement here is one we will repeat in writing when you ask.

Where a detail depends on something not yet settled — a named provider, a region, an acknowledgement window — it is marked [TO BE CONFIRMED] rather than filled in with a plausible answer. A gap you can see is worth more to a reviewer than a sentence that reads well and is not yet true.

This page describes our practice. For a customer, the binding version is the agreement we sign, and where the two differ that agreement governs the data it covers.

Controls

How your data is protected

Six things that are true of every fleet we run, not options you have to negotiate for.

  • Encrypted in transit and at rest

    Every request to this site and to any agent surface runs over HTTPS. Data held on our behalf is encrypted at rest by the platforms it sits on.

  • Least privilege by default

    An agent gets the narrowest access that lets it do the job in the brief. You grant it, it is scoped to named systems, and you can revoke it without involving us.

  • Every action is traceable

    Agents write to one audit trail. Any output can be traced back to the inputs and the decisions that produced it, which is also how you review one.

  • Consequential actions need approval

    Anything that leaves your systems — sending, spending, publishing, deleting — sits behind an approval step rather than running unattended.

  • Isolated per engagement

    One customer's brief, context and audit trail are never visible to another customer's fleet. Nothing is pooled across engagements.

  • Kept only while it is needed

    We hold what an engagement needs for as long as it needs it, then delete it. The retention window is set in the agreement rather than by us alone.

Commitments

What we will not do with your data

  • Your data never trains a model

    Nothing you send us, and nothing your fleet touches, is used to train or fine-tune a model — ours or anyone else's. We do not grant that right to a provider on your behalf.

  • Your prompts go only where the brief says

    The model providers a fleet may call are named before work starts. Adding one is a change you approve, not a change we make quietly.

  • You can take it back and leave

    On request we return what we hold in a usable format and delete our copies. There is no export fee, no notice period for asking, and no clause that makes leaving expensive.

Subprocessors

Who else processes data

We publish the category before we can publish the name, so you can see the shape of the disclosure now and hold us to finishing it. Named providers and their regions are confirmed in writing before an engagement starts, and a change to this list is a change you are told about.

Categories of service provider that may process data on our behalf.
ServiceWhat it doesProvider and region
Website hostingServes these pages and produces short-term request logs. Sets no cookies of its own, and is the only thing contacted at all until a visitor accepts analytics.Our hosting provider, United States
Website analyticsCounts page views and link clicks, and only after a visitor accepts. Never loaded before consent, and never used for advertising.Google LLC (Google Analytics 4)
Session analyticsRecords an anonymised replay of the page with text masked, and only after a visitor accepts. Never loaded before consent.Microsoft Corporation (Clarity)
EmailCarries correspondence with us, including anything you choose to send to our published address.Google LLC (Gmail / Google Workspace)
Models and providersRun the models behind the work we deliver, and are never given training rights over your data.Named in the engagement agreement before any work starts.

Questions a security review asks

The ones we are asked most often, answered as directly as we can. If your review has a question that is not here, send it and we will answer it in writing.

  • Do you train models on our data?

    No. Nothing you send us and nothing your fleet touches is used to train or fine-tune a model, ours or a provider's. Where a model provider offers training on submitted data as a default, we turn it off, and we will show you that setting.

  • Where is our data stored?

    In the regions named in your agreement. We confirm the storage region and the processing region separately, because a model call can leave the region its storage sits in and that difference is usually what a review is actually asking about.

  • How long do you keep it?

    For as long as the engagement needs it, then we delete it. The specific window is written into the agreement rather than left to our discretion, so it is a number you can point at rather than a policy you have to trust.

  • Can we get our data back, or have it deleted?

    Yes, on request and at any time. We return what we hold in a usable format and delete our copies, including from the audit trail where you ask us to and the law allows it. There is no fee and no notice period for asking.

Documents and policies

Everything above in its binding form. The first three are published; the fourth we send on request.

  1. 1
  2. 2
  3. 3
  4. 4

Report a security issue

If you have found something, tell us before you tell anyone else and we will treat you as having done us a favour. Include the steps to reproduce it and anything you think we will need to see it ourselves.

We acknowledge every report within [TO BE CONFIRMED] working days and tell you what we intend to do about it. In return we ask that you give us a reasonable window before publishing, and that you do not access, change or keep anyone else's data while investigating.

Put “Security” in the subject line.