Skip to content
ComplyMynt

Trust Center

We hold your most sensitive findings. That comes with obligations.

This page is maintained by ComplyMynt to answer common security, privacy, and confidentiality questions about how we work. It describes our practices — it is not a third-party certification.

Secure handling

How we treat client material

Least-privilege access

We request the narrowest access that completes the work — usually none beyond public surfaces and documents you send us. Repository or staging access is scoped, time-bound, and revoked at close.

Encrypted evidence handling

Screenshots, traces, and documents are stored encrypted at rest and in transit, in a per-client workspace, accessible only to the named engagement team.

Named handlers

Every engagement lists the individuals who may access your material. Changes to that list are recorded and shared with you.

Destruction on request

Evidence is retained for the agreed period and destroyed on request, with written confirmation. Reports remain yours to keep or share.

Non-intrusive testing

Security reviews are observational. We do not perform exploitation, load testing, or access to data we were not explicitly authorized to view.

Responsible disclosure

If we discover a serious issue outside the engagement scope, we notify your named contact privately and immediately, and never publish without written permission.

Responsible disclosure

Found something in a ComplyMynt property?

We welcome good-faith reports and respond to every one. We will not pursue legal action against researchers who follow this policy.

  1. 1Email info@complymynt.com with a description and reproduction steps.
  2. 2We acknowledge within two business days and assign a named owner.
  3. 3We agree a remediation timeline with you and keep you updated in writing.
  4. 4We credit reporters publicly when they wish to be credited.

Please avoid automated scanning that degrades service, and never access data that is not yours.

Process

How an engagement moves, step by step

Each phase has a named owner, a written deliverable, and a defined handling standard for your material.

  1. 1

    Scoping and mutual NDA

    Day 0–2

    We agree surfaces, exclusions, and named handlers in writing before any product detail changes hands.

  2. 2

    Evidence collection

    Day 3–6

    Automated crawl plus manual flow replay. Everything captured lands in an encrypted, per-client workspace.

  3. 3

    Specialist review

    Day 7–9

    Each domain lead verifies findings by hand, assigns severity, and records reproduction steps and evidence links.

  4. 4

    Report and walkthrough

    Day 10–12

    You receive a board-ready summary, an engineer-ready backlog, and a live session to challenge every conclusion.

  5. 5

    Remediation and re-verification

    Ongoing

    Our engineers ship fixes as pull requests, then we re-verify and close findings against the original evidence.

Evidence

Interactive sample findings and remediation outcomes

Select a finding to see the exposure, then compare the state before and after remediation.

Exposure

Three vendor tags loaded on first paint in the EU, before any consent signal existed — creating direct regulatory exposure on every European session.

Remediation shipped

Tag manager gated behind a server-verified consent signal, with an automated regression test blocking pre-consent network calls.

Remediation impact

After

Consent stack at close

  • 0 tags firing pre-consent
  • Signed consent log, 25-month retention
  • Reject-all blocks at tag manager
  • Regional policies enforced server-side

Scorecards

Our own operational posture

Self-reported metrics from our internal control reviews. Evidence available under NDA — this is not a third-party certification.

0

Engagements under NDA

Mutual, pre-disclosure

0

Evidence encrypted at rest

Per-client workspaces

0

Access revoked at close

Verified checklist

0

Disclosure SLA met

Two business days

Standards

Frameworks our reviews are mapped to

These describe the standards our audit methodology references. They are not claims that ComplyMynt or your product is certified.

GDPR / UK GDPR

Lawful basis, transparency, data-subject flows, transfers.

CPRA and US state laws

Sale/share signals, opt-out honoring, sensitive data.

TCPA

Express written consent capture, retention, and revocation paths.

WCAG 2.2 AA

Manual plus automated conformance across critical journeys.

EU AI Act readiness

Transparency, disclosure, and risk classification posture.

OWASP ASVS (observational)

Public surface hardening reviewed, never exploited.

Enterprise readiness

What procurement usually asks us

Shared responsibility: these statements describe ComplyMynt's own practices. Your product's controls remain yours, and your customers' obligations remain theirs.

Mutual NDA
Standard before any product detail is exchanged
Insurance
Professional liability coverage; certificate on request
Subcontractors
Disclosed in advance; bound by the same terms
Data location
United States; alternatives available on request
Retention
Default 90 days post-engagement, configurable
Questionnaires
We complete your vendor security questionnaire