Security & Trust

The security review, answered before you ask it.

Isolation, sovereignty, delegated authority and data policy — in the same terms your security team will use to evaluate it.

Sovereignty

Your data, your infrastructure, your models.

Infrastructure

Cloud infrastructure certified to ISO/IEC 27001 and SOC 2. AES-256 encryption at rest, TLS 1.2+ in transit.

Tenant isolation

Row-level security is enforced at the database layer — one customer's data cannot be read or written by another's, even on shared infrastructure.

Model sovereignty

Frontier, open-weight or locally hosted models, chosen per workload — no forced dependency on a single provider.

No cross-tenant data leakage

Isolation is enforced by the database, not application code.

An application bug — a missing filter, a bad join — cannot cross the tenant boundary, because the boundary isn't the application's job to enforce.

0

Access policies across 88 tables

Tested continuously with planted-violation tests.

Delegated authority & audit

Every action is approved, then provable.

Ask before acting, act and notify, or act autonomously — set per action, per agent, per tenant. See the full model on the Platform page.

Immutable audit record

Every agent action produces a searchable, exportable record that can't be edited after the fact — evidence for an auditor, not a claim you're asking them to trust.

Data policy & legal position

Stated plainly, not buried in a PDF.

RoleParty
ControllerYou, the customer
ProcessorMyntriq Pte Ltd

Retention

Account duration plus 12 months. 30 days after termination.

Certification, honestly stated

SOC 2 Type II and ISO 27001 are not held in Myntriq's own name — we do not currently hold third-party security certifications in our own name. The platform runs on cloud infrastructure certified to ISO/IEC 27001 and SOC 2.

Have a question your review board needs answered directly?

Talk to us before you evaluate — or after.