Data Collection, Storage & Processing

How MandateMind collects, stores, processes, and protects customer data. Updated for 2026.

Overview

MandateMind AI is a cloud‑based Governance, Risk, and Compliance (GRC) platform. This page explains how data enters the system, where it is stored, how it is processed, and the security controls that protect it. MandateMind does not scan cloud environments, ingest logs, or pull configuration data from client systems. All data is user‑provided or generated within the platform.

1. What Data MandateMind Collects

📁 User‑Provided Data

Evidence files, control responses, mandate mappings, assessments, notes, and remediation details.

👤 Identity & Account Data

Name, email, role (Admin, Client, Auditor), authentication metadata.

📊 Platform Metadata

Evidence scoring metadata, drift detection metadata, audit logs, timestamps, file integrity hashes.

🚫 What We Do NOT Collect

No cloud configuration data, logs, IAM policies, endpoint telemetry, or sensitive PII.

2. How Data Enters MandateMind

📥 Manual Uploads

Users upload evidence files directly through the UI.

⌨ Manual Input

Users enter control responses, mandate mappings, and remediation notes.

🔌 API (Optional)

Automate evidence uploads and control updates. No automatic ingestion from client systems.

3. How Data Is Stored

☁ AWS Hosting

MandateMind is hosted on Amazon Web Services (AWS).

🗄 Storage Architecture

Evidence → S3, App Data → RDS PostgreSQL, Logs → CloudWatch, Backups → Encrypted S3.

🔐 Encryption

TLS 1.2+ in transit, AES‑256 at rest, SHA‑256 integrity hashing.

🧩 Tenant Isolation

Logical separation, row‑level access controls, segregated evidence paths, strict RBAC.

4. How Data Is Processed

📁 Evidence Processing

Encrypted storage, metadata extraction, control linking, freshness scoring.

⚠ Drift Detection

Analyzes evidence timestamps, control responses, and mandate mappings.

🤖 AI Processing

Summaries, mappings, gap detection. AI models do not train on client data.

5. Access Controls & Security

🛡 RBAC Roles

Admin, Client, Auditor.

🔐 Authentication

Email + password, optional MFA, session expiration, device/session logging.

📜 Audit Logging

Logins, evidence uploads, control changes, mandate mappings, permission changes.

6. Subprocessors

7. Data Residency

All customer data is stored in United States AWS regions. Additional regions may be added based on demand.

8. Data Retention & Deletion

9. Compliance Posture

MandateMind is actively pursuing SOC 2 Type II certification.