How MandateMind collects, stores, processes, and protects customer data. Updated for 2026.
MandateMind AI is a cloud‑based Governance, Risk, and Compliance (GRC) platform. This page explains how data enters the system, where it is stored, how it is processed, and the security controls that protect it. MandateMind does not scan cloud environments, ingest logs, or pull configuration data from client systems. All data is user‑provided or generated within the platform.
Evidence files, control responses, mandate mappings, assessments, notes, and remediation details.
Name, email, role (Admin, Client, Auditor), authentication metadata.
Evidence scoring metadata, drift detection metadata, audit logs, timestamps, file integrity hashes.
No cloud configuration data, logs, IAM policies, endpoint telemetry, or sensitive PII.
Users upload evidence files directly through the UI.
Users enter control responses, mandate mappings, and remediation notes.
Automate evidence uploads and control updates. No automatic ingestion from client systems.
MandateMind is hosted on Amazon Web Services (AWS).
Evidence → S3, App Data → RDS PostgreSQL, Logs → CloudWatch, Backups → Encrypted S3.
TLS 1.2+ in transit, AES‑256 at rest, SHA‑256 integrity hashing.
Logical separation, row‑level access controls, segregated evidence paths, strict RBAC.
Encrypted storage, metadata extraction, control linking, freshness scoring.
Analyzes evidence timestamps, control responses, and mandate mappings.
Summaries, mappings, gap detection. AI models do not train on client data.
Admin, Client, Auditor.
Email + password, optional MFA, session expiration, device/session logging.
Logins, evidence uploads, control changes, mandate mappings, permission changes.
All customer data is stored in United States AWS regions. Additional regions may be added based on demand.
MandateMind is actively pursuing SOC 2 Type II certification.