Security Trust Center

Built to protect
your data.

Our information security programme is designed to protect the confidentiality, integrity, and availability of customer data. This page documents our security controls, data protection practices, and the policies governing how we operate.

GDPR Compliant Swiss nDSG Compliant ISMS aligned with ISO/IEC 27001:2022
Coverage
Our Security Perimeter

The security controls and commitments described here apply to the development, operation, and maintenance of the Mindfuel platform, delivered by Mindfuel AG and the teams described below.

Legal Entity
Mindfuel AG
Registered in Switzerland. Accountable entity for all data processing and information security obligations across the Mindfuel platform.
Data Access
Restricted & Policy-Governed
Access to customer data is restricted to the Product Team and Value Acceleration Team. Security policies and training requirements apply to all Mindfuel employees and contractors across all functions.
Infrastructure
Google Cloud Platform
All production workloads hosted on GCP in Frankfurt, Germany (europe-west3). No on-premises infrastructure.
Frameworks & Regulations
What We Align To

Our information security programme is built on internationally recognised practices and meets applicable legal requirements across all operating jurisdictions.

GDPR

Mindfuel processes personal data in compliance with the EU General Data Protection Regulation. This covers lawful basis, data subject rights, retention, breach notification, and international transfers via Standard Contractual Clauses where applicable.

Swiss nDSG

As a Swiss entity, Mindfuel AG complies with the revised Federal Act on Data Protection (nDSG, effective September 2023). Obligations under nDSG are integrated alongside GDPR requirements in our data protection programme.

ISO/IEC 27001:2022

Our ISMS is structured around the requirements and controls of ISO/IEC 27001:2022, the internationally recognised standard for information security management. Control coverage is documented in full and available to authorised contacts on request.

Security Controls
How We Protect Your Data

Our control catalogue is organised into ten security domains. Each entry shows what we do, how we implement it, and the policy that governs it. ISO 27001 control references are shown for each item.

Click any domain to expand the full control list. Policy documents are available to authorised contacts via the Policy Library.

Physical controls: A number of controls relating to physical facilities and premises have been assessed as not applicable to our operations. We are a fully remote company with no offices, server rooms, or data centres under our control. All infrastructure is hosted on Google Cloud. Documentation of these exclusions is available on request.
Policy Library
Security Documentation

Mindfuel maintains a comprehensive set of policies and procedures governing our information security programme. Documents are available to authorised contacts via our Policy Library.

Core ISMS
Information Security Policy
Top-level policy establishing our information security objectives, principles, and management framework.
View document →
Core ISMS
ISMS Manual
Defines the scope, governance structure, and operating model of our Information Security Management System.
View document →
Roles
Information Security Roles & Responsibilities
Defines accountability and responsibility assignments for all information security roles across the organisation.
View document →
Access & Identity
Access Management Policy
Governs provisioning, modification, review, and revocation of access to systems and data.
View document →
Access & Identity
Password Management Policy
Defines requirements for password strength, storage, rotation, and MFA enforcement across all systems.
View document →
Data
Information Classification Policy
Establishes the three-level classification scheme (Confidential / Internal Use / Public) and associated handling requirements.
View document →
Data
Data & Record Retention Policy
Defines retention periods by data type and requirements for secure deletion upon expiry or customer instruction.
View document →
Acceptable Use
Acceptable Usage Policy
Governs the acceptable use of our information assets, systems, devices, and approved tools by all personnel.
View document →
People
People & Employment Security Policy
Covers pre-employment screening, security obligations in contracts, awareness training, and exit procedures.
View document →
People
Disciplinary Policy
Defines the formal disciplinary process for security policy violations and personal data misuse.
View document →
Endpoint
Mobile Device & Remote Work Policy
Specifies security requirements for all endpoint devices and remote working arrangements across the fully distributed workforce.
View document →
Development
Secure Development Policy
Defines security requirements throughout the software development lifecycle, from design through to deployment and maintenance.
View document →
Development
Change Management Procedure
Governs the classification, risk assessment, approval, testing, and rollback process for all changes to systems and infrastructure.
View document →
Monitoring
Log Management & Monitoring Policy
Governs the collection, retention, protection, and review of security-relevant logs and monitoring activities.
View document →
Vendors
Vendor Management Policy
Covers vendor classification, due diligence, contractual controls, ongoing oversight, and offboarding for all third-party relationships.
View document →
Incident
Incident Management Procedure
Defines the end-to-end process for identifying, triaging, responding to, and learning from information security incidents.
View document →
Incident
Data Breach Management Procedure
Defines the process for identifying, containing, and notifying data breaches in line with GDPR Art. 33 and Swiss nDSG obligations.
View document →
Continuity
Business Continuity & DR Policy
Defines recovery objectives, backup strategy, resilience measures, and procedures for maintaining operations during disruption.
View document →
Governance
Internal Audit & Corrective Action Procedure
Governs the planning, execution, and follow-up of internal audits, including corrective action tracking.
View document →
Governance
Risk Management Procedure
Defines the methodology for identifying, assessing, treating, and reviewing information security risks.
View document →
Privacy
Privacy Notice
Public-facing notice describing how Mindfuel processes personal data, the lawful bases applied, and data subject rights.
View document →
Security Testing
Penetration Test Report
Annual external penetration test conducted by an independent third party. Executive summary available to authorised contacts under NDA.
View document →
Policy documents are made available to authorised contacts on request. Please reach out to your Mindfuel contact to request access.
Data Processing
Sub-processors

Mindfuel uses the following third-party services in the delivery of our platform. All sub-processors are subject to due diligence, contractual data protection obligations, and Data Processing Agreements (DPAs) where required under GDPR Art. 28.

Sub-processor Purpose Data Location Transfer Basis
Google Cloud Platform
Cloud infrastructure & hosting
Production infrastructure, data storage, compute, and networking for the Mindfuel product EU EU Hosting
Auth0 (Okta)
Customer-facing authentication
Authentication, authorisation, and session management for platform users EU EU Hosting
Jimo
In-app onboarding & user feedback
Product tours, onboarding checklists, in-app announcements, and NPS / feedback features EU EU Hosting
Mailjet
Transactional email delivery
Service-related and transactional emails from the product, such as invitations and access communications EU EU Hosting
Datadog
Application monitoring & logging
Performance monitoring, log aggregation, alerting, and security event detection USA SCCs
Sentry
Error monitoring & diagnostics
Application error detection, diagnostics, and troubleshooting for the Mindfuel product USA SCCs
n8n
Workflow automation
Process automation and system integrations connecting Mindfuel to other internal tools EU EU Hosting
Further sub-processors are documented in our full sub-processor list, available to authorised contacts on request.
International data transfers to sub-processors outside the EEA are governed by Standard Contractual Clauses (SCCs) pursuant to GDPR Art. 46(2)(c). For Swiss data subjects, equivalent transfer mechanisms under nDSG apply.
Common Questions
Frequently Asked Questions

Answers to the questions we receive most often from customers and prospects during security reviews.

Questions about
our security?

For security-related enquiries or requests to access policy documentation, please reach out to your Mindfuel contact directly.

Security Enquiries & Document Access
hello@mindfuel.ai
Data Protection & GDPR Enquiries
privacy@mindfuel.ai