Least-privilege access
We request the narrowest access that completes the work — usually none beyond public surfaces and documents you send us. Repository or staging access is scoped, time-bound, and revoked at close.
Trust Center
This page is maintained by ComplyMynt to answer common security, privacy, and confidentiality questions about how we work. It describes our practices — it is not a third-party certification.
Secure handling
We request the narrowest access that completes the work — usually none beyond public surfaces and documents you send us. Repository or staging access is scoped, time-bound, and revoked at close.
Screenshots, traces, and documents are stored encrypted at rest and in transit, in a per-client workspace, accessible only to the named engagement team.
Every engagement lists the individuals who may access your material. Changes to that list are recorded and shared with you.
Evidence is retained for the agreed period and destroyed on request, with written confirmation. Reports remain yours to keep or share.
Security reviews are observational. We do not perform exploitation, load testing, or access to data we were not explicitly authorized to view.
If we discover a serious issue outside the engagement scope, we notify your named contact privately and immediately, and never publish without written permission.
Responsible disclosure
We welcome good-faith reports and respond to every one. We will not pursue legal action against researchers who follow this policy.
Please avoid automated scanning that degrades service, and never access data that is not yours.
Process
Each phase has a named owner, a written deliverable, and a defined handling standard for your material.
We agree surfaces, exclusions, and named handlers in writing before any product detail changes hands.
Automated crawl plus manual flow replay. Everything captured lands in an encrypted, per-client workspace.
Each domain lead verifies findings by hand, assigns severity, and records reproduction steps and evidence links.
You receive a board-ready summary, an engineer-ready backlog, and a live session to challenge every conclusion.
Our engineers ship fixes as pull requests, then we re-verify and close findings against the original evidence.
Evidence
Select a finding to see the exposure, then compare the state before and after remediation.
Exposure
Three vendor tags loaded on first paint in the EU, before any consent signal existed — creating direct regulatory exposure on every European session.
Remediation shipped
Tag manager gated behind a server-verified consent signal, with an automated regression test blocking pre-consent network calls.
Remediation impact
After
Scorecards
Self-reported metrics from our internal control reviews. Evidence available under NDA — this is not a third-party certification.
Engagements under NDA
Mutual, pre-disclosure
Evidence encrypted at rest
Per-client workspaces
Access revoked at close
Verified checklist
Disclosure SLA met
Two business days
Standards
These describe the standards our audit methodology references. They are not claims that ComplyMynt or your product is certified.
Lawful basis, transparency, data-subject flows, transfers.
Sale/share signals, opt-out honoring, sensitive data.
Express written consent capture, retention, and revocation paths.
Manual plus automated conformance across critical journeys.
Transparency, disclosure, and risk classification posture.
Public surface hardening reviewed, never exploited.
Enterprise readiness
Shared responsibility: these statements describe ComplyMynt's own practices. Your product's controls remain yours, and your customers' obligations remain theirs.