The security review, answered before you ask it.
Isolation, sovereignty, delegated authority and data policy — in the same terms your security team will use to evaluate it.
Your data, your infrastructure, your models.
Infrastructure
Cloud infrastructure certified to ISO/IEC 27001 and SOC 2. AES-256 encryption at rest, TLS 1.2+ in transit.
Tenant isolation
Row-level security is enforced at the database layer — one customer's data cannot be read or written by another's, even on shared infrastructure.
Model sovereignty
Frontier, open-weight or locally hosted models, chosen per workload — no forced dependency on a single provider.
Isolation is enforced by the database, not application code.
An application bug — a missing filter, a bad join — cannot cross the tenant boundary, because the boundary isn't the application's job to enforce.
Access policies across 88 tables
Tested continuously with planted-violation tests.
Every action is approved, then provable.
Ask before acting, act and notify, or act autonomously — set per action, per agent, per tenant. See the full model on the Platform page.
Immutable audit record
Every agent action produces a searchable, exportable record that can't be edited after the fact — evidence for an auditor, not a claim you're asking them to trust.
Stated plainly, not buried in a PDF.
| Role | Party |
|---|---|
| Controller | You, the customer |
| Processor | Myntriq Pte Ltd |
Retention
Account duration plus 12 months. 30 days after termination.
Certification, honestly stated
SOC 2 Type II and ISO 27001 are not held in Myntriq's own name — we do not currently hold third-party security certifications in our own name. The platform runs on cloud infrastructure certified to ISO/IEC 27001 and SOC 2.
Everything your legal and security teams will ask for.
The formal data processor agreement for customers under PDPA and GDPR.
How we collect, use, and protect personal data within the MyntriqOS platform.
How long we retain different categories of data, and how to request deletion.
The third-party services we use to deliver MyntriqOS.
Infrastructure security, tenant isolation, encryption, audit logging, and incident response.
What cookies MyntriqOS uses and how to control them.
How MyntriqOS uses AI, oversight controls, customer obligations, and prohibited uses.
How we select, route, and govern the AI models available through MyntriqOS.
Our values, principles, and practical commitments around building and deploying AI responsibly.
Subscription terms, acceptable use, intellectual property, liability, and governing law.
Have a question your review board needs answered directly?
Talk to us before you evaluate — or after.