Loading...
Loading...
Customer truth is sensitive. We protect it with enterprise-grade security, strict compliance standards, and a zero-trust architecture.
Our founding team has deep information security experience. We are actively pursuing formal certification through Vanta and treat compliance as a first-class priority.
SOC 2
Type II: In Progress via Vanta
GDPR
In Progress via Vanta
CCPA
In Progress via Vanta
HIPAA
Safeguards in Place
ISO 27001
On Roadmap
All data is encrypted at rest and in transit using TLS 1.2 or higher. We do not store voice recordings, only transcripts and derived emotion/sentiment signals, under your retention controls. We enforce strict transport security protocols across all services.
Data is hosted on AWS (US-East) with SOC 2 certified infrastructure. Regular penetration testing and vulnerability assessments keep our systems hardened.
Interview data is anonymized by default. We do not store personal identifiers from respondents unless explicitly configured by the client.
Customer interview data is never used to train AI models. Your data remains confidential and is used solely for your research purposes.
Granular permissions, SSO integration, and audit logs ensure that only authorized personnel access your data. Full accountability at every level.
We support Standard Contractual Clauses for EU data transfers and are preparing for EU-U.S. Data Privacy Framework certification.
You are the Data Controller. ReadingMinds acts as the Data Processor. A DPA can be signed to formalize these roles.
In compliance with GDPR's “right to be forgotten,” we facilitate permanent data deletion upon request. Export your data first; deletion is irreversible.
If sensitive information or PII is shared during an interview, the AI automatically moves to the next question and strips out such data.
Our team is happy to walk through our security architecture, provide compliance documentation, or schedule a security review.