Security and privacy at Myndboosters AI
Read this first
What we claim, and what we do not
Myndboosters AI holds no third-party security certification today. There is no SOC 2 report, no ISO 27001 certificate, no CASA assessment and no PCI DSS attestation — which is why you will not find a row of badges on this page. A logo you cannot ask for the report behind is decoration, and we would rather tell you the position than let you infer it.
What follows is a description of how we actually work: what an agent can reach, who else sees the data, what we keep and for how long, and what we will not do with it. Every statement here is one we will repeat in writing when you ask.
Where a detail depends on something not yet settled — a named provider, a region, an acknowledgement window — it is marked [TO BE CONFIRMED] rather than filled in with a plausible answer. A gap you can see is worth more to a reviewer than a sentence that reads well and is not yet true.
This page describes our practice. For a customer, the binding version is the agreement we sign, and where the two differ that agreement governs the data it covers.
Controls
How your data is protected
Six things that are true of every fleet we run, not options you have to negotiate for.
Encrypted in transit and at rest
Every request to this site and to any agent surface runs over HTTPS. Data held on our behalf is encrypted at rest by the platforms it sits on.
Least privilege by default
An agent gets the narrowest access that lets it do the job in the brief. You grant it, it is scoped to named systems, and you can revoke it without involving us.
Every action is traceable
Agents write to one audit trail. Any output can be traced back to the inputs and the decisions that produced it, which is also how you review one.
Consequential actions need approval
Anything that leaves your systems — sending, spending, publishing, deleting — sits behind an approval step rather than running unattended.
Isolated per engagement
One customer's brief, context and audit trail are never visible to another customer's fleet. Nothing is pooled across engagements.
Kept only while it is needed
We hold what an engagement needs for as long as it needs it, then delete it. The retention window is set in the agreement rather than by us alone.
Commitments
What we will not do with your data
Your data never trains a model
Nothing you send us, and nothing your fleet touches, is used to train or fine-tune a model — ours or anyone else's. We do not grant that right to a provider on your behalf.
Your prompts go only where the brief says
The model providers a fleet may call are named before work starts. Adding one is a change you approve, not a change we make quietly.
You can take it back and leave
On request we return what we hold in a usable format and delete our copies. There is no export fee, no notice period for asking, and no clause that makes leaving expensive.
Subprocessors
Who else processes data
We publish the category before we can publish the name, so you can see the shape of the disclosure now and hold us to finishing it. Named providers and their regions are confirmed in writing before an engagement starts, and a change to this list is a change you are told about.
| Service | What it does | Provider and region |
|---|---|---|
| Website hosting | Serves these pages and produces short-term request logs. Sets no cookies of its own, and is the only thing contacted at all until a visitor accepts analytics. | Our hosting provider, United States |
| Website analytics | Counts page views and link clicks, and only after a visitor accepts. Never loaded before consent, and never used for advertising. | Google LLC (Google Analytics 4) |
| Session analytics | Records an anonymised replay of the page with text masked, and only after a visitor accepts. Never loaded before consent. | Microsoft Corporation (Clarity) |
| Carries correspondence with us, including anything you choose to send to our published address. | Google LLC (Gmail / Google Workspace) | |
| Models and providers | Run the models behind the work we deliver, and are never given training rights over your data. | Named in the engagement agreement before any work starts. |
Questions a security review asks
The ones we are asked most often, answered as directly as we can. If your review has a question that is not here, send it and we will answer it in writing.
Documents and policies
Everything above in its binding form. The first three are published; the fourth we send on request.
- 1
/privacy-policy
- 2
/terms-of-service
- 3
- 4
mailto:hello@myndboosters.com
Report a security issue
If you have found something, tell us before you tell anyone else and we will treat you as having done us a favour. Include the steps to reproduce it and anything you think we will need to see it ourselves.
We acknowledge every report within [TO BE CONFIRMED] working days and tell you what we intend to do about it. In return we ask that you give us a reasonable window before publishing, and that you do not access, change or keep anyone else's data while investigating.
Put “Security” in the subject line.