Skip to content
ComplyMynt

Trust Center

We hold your most sensitive findings. That comes with obligations.

This page is maintained by ComplyMynt to answer common security, privacy, and confidentiality questions about how we work. It describes our practices — it is not a third-party certification.

Secure handling

How we treat client material

Least-privilege access

We request the narrowest access that completes the work — usually none beyond public surfaces and documents you send us. Repository or staging access is scoped, time-bound, and revoked at close.

Encrypted evidence handling

Screenshots, traces, and documents are stored encrypted at rest and in transit, in a per-client workspace, accessible only to the named engagement team.

Named handlers

Every engagement lists the individuals who may access your material. Changes to that list are recorded and shared with you.

Destruction on request

Evidence is retained for the agreed period and destroyed on request, with written confirmation. Reports remain yours to keep or share.

Non-intrusive testing

Security reviews are observational. We do not perform exploitation, load testing, or access to data we were not explicitly authorized to view.

Responsible disclosure

If we discover a serious issue outside the engagement scope, we notify your named contact privately and immediately, and never publish without written permission.

Responsible disclosure

Found something in a ComplyMynt property?

We welcome good-faith reports and respond to every one. We will not pursue legal action against researchers who follow this policy.

  1. 1Email info@complymynt.com with a description and reproduction steps.
  2. 2We acknowledge within two business days and assign a named owner.
  3. 3We agree a remediation timeline with you and keep you updated in writing.
  4. 4We credit reporters publicly when they wish to be credited.

Please avoid automated scanning that degrades service, and never access data that is not yours.

Process

How an engagement moves, step by step

Each phase has a named owner, a written deliverable, and a defined handling standard for your material.

  1. 1

    Scoping and mutual NDA

    Day 0–2

    We agree surfaces, exclusions, and named handlers in writing before any product detail changes hands.

  2. 2

    Evidence collection

    Day 3–6

    Automated crawl plus manual flow replay. Everything captured lands in an encrypted, per-client workspace.

  3. 3

    Specialist review

    Day 7–9

    Each domain lead verifies findings by hand, assigns severity, and records reproduction steps and evidence links.

  4. 4

    Report and walkthrough

    Day 10–12

    You receive a board-ready summary, an engineer-ready backlog, and a live session to challenge every conclusion.

  5. 5

    Remediation and re-verification

    Ongoing

    Our engineers ship fixes as pull requests, then we re-verify and close findings against the original evidence.

Evidence

Interactive sample findings and remediation outcomes

Select a finding to see the exposure, then compare the state before and after remediation.

Exposure

Three vendor tags loaded on first paint in the EU, before any consent signal existed — creating direct regulatory exposure on every European session.

Remediation shipped

Tag manager gated behind a server-verified consent signal, with an automated regression test blocking pre-consent network calls.

Remediation impact

After

Consent stack at close

  • 0 tags firing pre-consent
  • Signed consent log, 25-month retention
  • Reject-all blocks at tag manager
  • Regional policies enforced server-side

Commitments

How we operate on every engagement

These are the working commitments we make in writing. They describe our own practices — they are not a third-party audit, attestation, or certification.

Mutual NDA first

Signed before any evidence or system detail changes hands.

Encrypted evidence

Per-client workspaces, encrypted in transit and at rest.

Access revoked at close

Scoped, time-bound credentials removed on a verified checklist.

Disclosure response

We acknowledge security reports within two business days.

Security & assurance

Frameworks our reviews are mapped to

These are the standards our audit methodology references. ComplyMynt does not hold, and does not claim, certification under any of them, and mapping does not certify your product.

GDPR / UK GDPR

Lawful basis, transparency, data-subject flows, transfers.

CPRA and US state laws

Sale/share signals, opt-out honoring, sensitive data.

TCPA

Express written consent capture, retention, and revocation paths.

WCAG 2.2 AA

Manual plus automated conformance across critical journeys.

EU AI Act readiness

Transparency, disclosure, and risk classification posture.

OWASP ASVS (observational)

Public surface hardening reviewed, never exploited.

Enterprise readiness

What procurement usually asks us

Shared responsibility: these statements describe ComplyMynt's own practices. Your product's controls remain yours, and your customers' obligations remain theirs.

Mutual NDA
Standard before any product detail is exchanged
Insurance
Professional liability coverage; certificate on request
Subcontractors
Disclosed in advance; bound by the same terms
Data location
United States; alternatives available on request
Retention
Default 90 days post-engagement, configurable
Questionnaires
We complete your vendor security questionnaire

Infrastructure

Where your evidence lives and how it is protected

Self-reported descriptions of ComplyMynt's own operating environment, current as of this page's last update.

Hosting
Evidence workspaces run on managed US cloud infrastructure with per-client isolation.
Encryption
TLS 1.2+ in transit and AES-256 at rest for all engagement material.
Access control
SSO with enforced MFA, role-scoped permissions, and quarterly access reviews.
Logging
Access to client workspaces is logged and reviewable by the client on request.
Backups
Encrypted daily backups, 30-day rolling window, restore tested twice a year.
Endpoints
Company devices are disk-encrypted, patch-managed, and remotely wipeable.

Subprocessors

Every vendor that can touch engagement material

We notify named contacts before adding a subprocessor with access to client evidence.

ComplyMynt subprocessors, purpose and data location
SubprocessorPurposeDataLocation
Managed US cloud providerEvidence storage and computeEngagement evidence, reportsUnited States
Email and productivity suiteCommunication and document deliveryContact details, reportsUnited States
Encrypted file transferDelivering reports and evidenceReports, evidence packagesUnited States
Issue trackerRemediation backlog handoff (opt-in)Finding titles, remediation stepsUnited States
Video conferencingKickoff and walkthrough sessionsMeeting metadataUnited States

Ask for the current signed list and data processing addendum at info@complymynt.com.

Responsible disclosure

Reporting a vulnerability to us

We welcome reports about ComplyMynt's own surfaces and commit to the handling below.

Acknowledgement

We confirm receipt of a report within two business days, with a named owner.

Assessment

Triage and severity classification within five business days, shared with the reporter.

Remediation

Critical issues on our own surfaces are addressed within 30 days, with status updates.

Safe harbor

Good-faith research on our surfaces will not be pursued legally. No data exfiltration or service disruption.

Status

All systems operational

Our evidence workspaces, reporting pipeline, and disclosure inbox are currently operating normally.

ComplyMynt system status
ServiceStatusLast checked
Evidence workspaceOperationalJust now
Report delivery portalOperationalJust now
Disclosure inboxOperationalJust now
Contact & intakeOperationalJust now

Report an issue to info@complymynt.com.