// Our security promise

Sicherheit bei Mindverse

Security is our fundamental promise — not an afterthought. An information security management system built to ISO 27001 keeps your data safe, your workspace private, and your information accurate: GDPR-compliant, encrypted, and hosted exclusively in Germany.

ISMS
built to ISO 27001:2022
DPA
EU SCC · Art. 28 GDPR
Hosting
100% Germany
mindverse · isms — written order
  • policy_classification active
  • policy_threat_incident_mgmt active
  • policy_access_management active
  • policy_secure_development active
  • policy_operations active
  • policy_cryptography active
  • policy_business_continuity active
  • policy_supplier_mgmt active
guideline → policies → procedures annex a · 93 controls

// Audited processes

We implement strict security protocols and verify their effectiveness in regular internal audits and penetration tests — accompanied by an external information security officer.

An external information security and data protection officer accompanies our ISMS. All details on data processing are in our privacy policy; our stance on responsible AI in our ethical principles.

// Protection goals

Three protection goals every measure has to answer to

Confidentiality, integrity, availability — C · I · A. Every rule and every technical measure in our ISMS exists to guarantee or improve these three goals.

C Vertraulichkeit

Confidentiality

What you do not want to share with third parties stays confidential. Classification and protection needs of every piece of information are governed by a dedicated policy — from labeling and transport to retention.

I Integrität

Integrity

You make business decisions with our results. Information must therefore never be distorted by errors or negligence — integrity checks are part of how we build.

A Verfügbarkeit

Availability

Systems have to deliver when you need them. Capacity management, backups and business-continuity plans keep the platform available — even when something goes wrong.

If any of the three goals is violated, it is a security incident — and triggers our incident management

// Defense in depth

Three lines of defense instead of one wall

There is no such thing as absolute security — whoever promises otherwise has not understood the problem. That is why we organize information security in multiple lines: prevent attacks, detect intruders early, and be prepared for the worst case.

The third line is a defense in itself: big attacks often start with a small disturbance meant to push teams into hectic ad-hoc work. Whoever has defined procedures keeps following well-thought-out rules — even then.

  1. Line 01

    Intrusion prevention

    The first line keeps unauthorized parties out of the systems in the first place: hardening, network segmentation, access controls, encryption.

  2. Line 02

    Intrusion detection

    The second line discovers and stops intruders early: monitoring, logging, and continuous observation of the entire platform.

  3. Line 03

    Incident response & BCM

    The third line is preparation for the worst case: defined procedures, breach management, and business-continuity plans for a fast return to normal operations.

// Security architecture

Six pillars that protect your data

From the data center to the vector database: every layer of the platform is built for confidentiality, integrity, and traceability.

01

Data security

Row-level access controls separate information cleanly by role and organizational unit — everyone sees exactly what they are allowed to see, and nothing more.

02

Vulnerability scans

Regular scans and penetration tests at critical points in the development cycle identify potential weaknesses before they become a risk.

03

GDPR compliance

Secure processing, data processing agreements under Art. 28, and mechanisms to exercise your data-subject rights — from access to erasure.

04

Your data is never used for training

Your content, documents, and prompts are never used to train LLMs. What you enter stays yours.

05

Instance separation

Enterprise customers can get a dedicated LLM instance that is physically and logically isolated from other customer environments.

06

Dedicated prompting and vector database

Prompting methods and the vector database are tailored to your use cases — for precise answers with citations from your own knowledge bases.

// The ISMS behind it

A management system that is lived — not just written down

Our information security management system is built to ISO 27001:2022 and follows the 93 controls of its Annex A: organizational, people, physical, and technological. It is not certified by an accredited body; it is consistently run to the standard. The written order has three levels: a guideline sets the principles, policies govern the how, and procedures keep the implementation current.

Responsibility is assigned to roles — from asset owner to service manager. Conflicts of interest are ruled out where it matters: nobody reviews their own work. And because threats change, the ISMS changes with them — rules that do not help get fixed instead of filed.

KISS

Keep it simple

Complexity correlates negatively with security. Simple, clear systems are systems you can control.

DENY ALL

Blocked until allowed

Access is denied by default and granted deliberately — never the other way around.

4 EYES

Four-eyes principle

No code reaches production without an independent review — nobody reviews their own work.

ZERO TRUST

Trust is not a control

Every request is verified, every permission justified — inside our own systems too.

policy register · the written order iso 27001:2022
  • klassifizierung

    Classification & protection needs

  • threat_incident

    Threat & incident management

  • bcm

    Business continuity

  • assets

    Asset management

  • lieferanten

    Supplier management

  • access

    Access management

  • people

    People controls

  • physical

    Physical security

  • development

    Secure development

  • operations

    Operations

  • krypto

    Cryptography & keys

  • compliance

    Compliance & knowledge

12 policies · registers & inventories instead of case-by-case decisions · accompanied by an external ciso / dpo

// GDPR in detail

GDPR compliance you get in writing

Compliance must not be a marketing word. That is why we answer your data protection officer's questions before they are asked — with a data processing agreement under Art. 28 GDPR based on the EU standard contractual clauses, and documented processes for every data-subject right.

Requirement Basis How Mindverse delivers
Data processing agreement Art. 28 GDPR Standardized DPA based on the EU standard contractual clauses (Implementing Decision 2021/915) — available on request at short notice.
Right of access Art. 15 GDPR Complete export of your data directly from the platform.
Right to erasure Art. 17 GDPR Documented deletion concepts; complete removal from all systems on request.
Breach notification Art. 33/34 GDPR Defined breach management: immediate notification with everything your report to the supervisory authority requires.
Data location Hosting Processing exclusively on servers in certified data centers in Germany.
Sub-processors Transparency Agreed list with advance notice of changes and a right to object — no hidden data flows.
Model training Purpose limitation Your content is never used to train AI models.

// Hosting & sovereign models

Data in Germany — and, if you want, the AI models too

Mindverse Studio is hosted exclusively in Germany. With our sovereign models such as GPT OSS 120B and DeepSeek V3.2, even inference itself runs on German infrastructure on request — your data never leaves the EU. And because the platform is LLM-independent, you keep the choice of model: OpenAI, Anthropic, Google, and Mistral via EU endpoints, or fully sovereign.

How companies work with this at scale is covered on AI for companies — the available plans including the sovereign option are on the pricing page.

AES-256 encryption

Encryption in transit (TLS) and at rest — for documents, knowledge bases, and chat histories.

SOC 2-oriented processes

Security and control processes built on the SOC 2 framework: documented and verifiable — without an attested SOC 2 report.

Pentests & monitoring

Regular penetration tests, intrusion detection, and continuous monitoring across the entire platform.

RBAC, SSO & audit logs

Role-based access across company, team, and user levels, SSO via OIDC, and complete audit logs.

// Responsible AI

AI that passes the audit

Secure AI does not end at the infrastructure. Protection against prompt injection, output filters, and per-team model policies keep AI results controllable. As a signatory of the Hamburg Declaration on Responsible AI, we publicly commit to transparent, responsible AI development.

  • Protection against prompt injection and misuse
  • Answers with citations from your knowledge bases
  • Human-in-the-loop approvals in workflows
  • Model policies and permissions per team

More on how citations work under texts with citations and knowledge bases.

// From practice

Secure AI process automation in practice: communications agency media.works saves over 40% of its time with Mindverse — in full GDPR compliance.

// Persona · Integrated pseudonymisation

Protect sensitive details before they reach the LLM.

A fine-tuned model detects personal details in context and replaces them with consistent pseudonyms. Explore pseudonymisation in Mindverse Studio, with nine data categories and re-identification for usable responses.

// FAQ

Frequently asked security questions

What security measures does Mindverse use?
Mindverse uses state-of-the-art security protocols, including data encryption, regular security reviews, and strict access controls.
How does Mindverse protect my data?
Your data is stored and processed in encrypted form. We comply with the General Data Protection Regulation (GDPR) and other international standards.
Is Mindverse GDPR-compliant?
Yes, Mindverse is fully GDPR-compliant and meets all legal requirements for data protection.
Is my data shared with third parties?
No, your data is never shared with third parties without your consent. Mindverse offers full transparency in data processing.
Which certifications does Mindverse hold?
Our information security management system is built to ISO 27001:2022 and aligned with the 93 controls of its Annex A. It is not currently certified by an accredited body, and there is no attested SOC 2 report. Our data centers in Germany are certified.
How does Mindverse secure its AI models?
Our AI models are reviewed regularly to prevent manipulation and ensure safe use.
Are there audits or reviews of the security standards?
Yes, Mindverse conducts regular internal and external security reviews as well as penetration tests.
Is my data deleted after use?
Yes, you have full control over your data. Upon request, we delete your data completely from our systems.
Is the Mindverse platform protected against cyberattacks?
Yes, Mindverse has robust protection against cyberattacks, including firewalls, intrusion detection systems, and continuous monitoring.
How is it ensured that the AI does not process sensitive data?
Our systems use strict filters and protocols to ensure that no sensitive or unauthorized data is processed.

// Start securely

Try the secure, GDPR-compliant AI suite

Boost your productivity without compromising on data protection — free for 7 days, hosted in Germany.

GDPR-COMPLIANT · SERVERS IN GERMANY · SOC 2-ORIENTED PROCESSES