Least-privilege access
We request the narrowest access that completes the work — usually none beyond public surfaces and documents you send us. Repository or staging access is scoped, time-bound, and revoked at close.
Trust Center
This page is maintained by ComplyMynt to answer common security, privacy, and confidentiality questions about how we work. It describes our practices — it is not a third-party certification.
Secure handling
We request the narrowest access that completes the work — usually none beyond public surfaces and documents you send us. Repository or staging access is scoped, time-bound, and revoked at close.
Screenshots, traces, and documents are stored encrypted at rest and in transit, in a per-client workspace, accessible only to the named engagement team.
Every engagement lists the individuals who may access your material. Changes to that list are recorded and shared with you.
Evidence is retained for the agreed period and destroyed on request, with written confirmation. Reports remain yours to keep or share.
Security reviews are observational. We do not perform exploitation, load testing, or access to data we were not explicitly authorized to view.
If we discover a serious issue outside the engagement scope, we notify your named contact privately and immediately, and never publish without written permission.
Responsible disclosure
We welcome good-faith reports and respond to every one. We will not pursue legal action against researchers who follow this policy.
Please avoid automated scanning that degrades service, and never access data that is not yours.
Process
Each phase has a named owner, a written deliverable, and a defined handling standard for your material.
We agree surfaces, exclusions, and named handlers in writing before any product detail changes hands.
Automated crawl plus manual flow replay. Everything captured lands in an encrypted, per-client workspace.
Each domain lead verifies findings by hand, assigns severity, and records reproduction steps and evidence links.
You receive a board-ready summary, an engineer-ready backlog, and a live session to challenge every conclusion.
Our engineers ship fixes as pull requests, then we re-verify and close findings against the original evidence.
Evidence
Select a finding to see the exposure, then compare the state before and after remediation.
Exposure
Three vendor tags loaded on first paint in the EU, before any consent signal existed — creating direct regulatory exposure on every European session.
Remediation shipped
Tag manager gated behind a server-verified consent signal, with an automated regression test blocking pre-consent network calls.
Remediation impact
After
Commitments
These are the working commitments we make in writing. They describe our own practices — they are not a third-party audit, attestation, or certification.
Mutual NDA first
Signed before any evidence or system detail changes hands.
Encrypted evidence
Per-client workspaces, encrypted in transit and at rest.
Access revoked at close
Scoped, time-bound credentials removed on a verified checklist.
Disclosure response
We acknowledge security reports within two business days.
Security & assurance
These are the standards our audit methodology references. ComplyMynt does not hold, and does not claim, certification under any of them, and mapping does not certify your product.
Lawful basis, transparency, data-subject flows, transfers.
Sale/share signals, opt-out honoring, sensitive data.
Express written consent capture, retention, and revocation paths.
Manual plus automated conformance across critical journeys.
Transparency, disclosure, and risk classification posture.
Public surface hardening reviewed, never exploited.
Enterprise readiness
Shared responsibility: these statements describe ComplyMynt's own practices. Your product's controls remain yours, and your customers' obligations remain theirs.
Infrastructure
Self-reported descriptions of ComplyMynt's own operating environment, current as of this page's last update.
Subprocessors
We notify named contacts before adding a subprocessor with access to client evidence.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Managed US cloud provider | Evidence storage and compute | Engagement evidence, reports | United States |
| Email and productivity suite | Communication and document delivery | Contact details, reports | United States |
| Encrypted file transfer | Delivering reports and evidence | Reports, evidence packages | United States |
| Issue tracker | Remediation backlog handoff (opt-in) | Finding titles, remediation steps | United States |
| Video conferencing | Kickoff and walkthrough sessions | Meeting metadata | United States |
Ask for the current signed list and data processing addendum at info@complymynt.com.
Responsible disclosure
We welcome reports about ComplyMynt's own surfaces and commit to the handling below.
Acknowledgement
We confirm receipt of a report within two business days, with a named owner.
Assessment
Triage and severity classification within five business days, shared with the reporter.
Remediation
Critical issues on our own surfaces are addressed within 30 days, with status updates.
Safe harbor
Good-faith research on our surfaces will not be pursued legally. No data exfiltration or service disruption.
Status
Our evidence workspaces, reporting pipeline, and disclosure inbox are currently operating normally.
| Service | Status | Last checked |
|---|---|---|
| Evidence workspace | Operational | Just now |
| Report delivery portal | Operational | Just now |
| Disclosure inbox | Operational | Just now |
| Contact & intake | Operational | Just now |
Report an issue to info@complymynt.com.