Our information security programme is designed to protect the confidentiality, integrity, and availability of customer data. This page documents our security controls, data protection practices, and the policies governing how we operate.
The security controls and commitments described here apply to the development, operation, and maintenance of the Mindfuel platform, delivered by Mindfuel AG and the teams described below.
Our information security programme is built on internationally recognised practices and meets applicable legal requirements across all operating jurisdictions.
Mindfuel processes personal data in compliance with the EU General Data Protection Regulation. This covers lawful basis, data subject rights, retention, breach notification, and international transfers via Standard Contractual Clauses where applicable.
As a Swiss entity, Mindfuel AG complies with the revised Federal Act on Data Protection (nDSG, effective September 2023). Obligations under nDSG are integrated alongside GDPR requirements in our data protection programme.
Our ISMS is structured around the requirements and controls of ISO/IEC 27001:2022, the internationally recognised standard for information security management. Control coverage is documented in full and available to authorised contacts on request.
Our control catalogue is organised into ten security domains. Each entry shows what we do, how we implement it, and the policy that governs it. ISO 27001 control references are shown for each item.
Click any domain to expand the full control list. Policy documents are available to authorised contacts via the Policy Library.
Mindfuel maintains a comprehensive set of policies and procedures governing our information security programme. Documents are available to authorised contacts via our Policy Library.
Mindfuel uses the following third-party services in the delivery of our platform. All sub-processors are subject to due diligence, contractual data protection obligations, and Data Processing Agreements (DPAs) where required under GDPR Art. 28.
| Sub-processor | Purpose | Data Location | Transfer Basis |
|---|---|---|---|
| Google Cloud Platform Cloud infrastructure & hosting |
Production infrastructure, data storage, compute, and networking for the Mindfuel product | EU | EU Hosting |
| Auth0 (Okta) Customer-facing authentication |
Authentication, authorisation, and session management for platform users | EU | EU Hosting |
| Jimo In-app onboarding & user feedback |
Product tours, onboarding checklists, in-app announcements, and NPS / feedback features | EU | EU Hosting |
| Mailjet Transactional email delivery |
Service-related and transactional emails from the product, such as invitations and access communications | EU | EU Hosting |
| Datadog Application monitoring & logging |
Performance monitoring, log aggregation, alerting, and security event detection | USA | SCCs |
| Sentry Error monitoring & diagnostics |
Application error detection, diagnostics, and troubleshooting for the Mindfuel product | USA | SCCs |
| n8n Workflow automation |
Process automation and system integrations connecting Mindfuel to other internal tools | EU | EU Hosting |
| Further sub-processors are documented in our full sub-processor list, available to authorised contacts on request. | |||
Answers to the questions we receive most often from customers and prospects during security reviews.
For security-related enquiries or requests to access policy documentation, please reach out to your Mindfuel contact directly.