Trust
What protects your data today, with the date each row was last checked — and what is not in place yet. Nothing on this page is a certification.
Each firm's documents and client answers live in that firm's own space. Our staff can see counts, hashes and status — never the content of a document or an answer — and every approval and every staff access grant is written to a ledger the firm can verify.
| Area | Control | Status | Last checked |
|---|---|---|---|
| Data location | Today the application, its database and all stored data run in Mandatum's own containers on a shared server in India. Dedicated hosting in the United States, or in the firm's own country, has not been started. | Not started | |
| Dedicated infrastructure | Mandatum runs in its own containers, with its own database and its own network, on a server that also hosts other businesses. A server used by Mandatum alone has not been started. | Not started | |
| Client data encryption | Every client answer, draft and generated document is sealed under a key that belongs to that one matter; erasing the matter destroys the key. The database volume beneath is not encrypted as a whole. | In place | |
| Disk encryption | Encryption of the database volume and backups at rest on the server. | Not started | |
| AI and client data | No client document and no client answer is sent to any AI model. Every model call passes one checkpoint that refuses client data; the only provider connected today returns fixed text; a firm can switch AI off for its workspace. | In place | |
| Vulnerability reporting | A published address for reporting a security problem (security.txt), with an acknowledgement. | Planned | |
| Card payments | No card details are taken or stored; there is no payment form. Card-industry (PCI) scope does not apply today. | Not offered | |
| Transport | All traffic over TLS on the canonical host; HTTP Strict Transport Security for one year, including subdomains. | In place | |
| Browser protections | A strict Content Security Policy (per-request nonces, no inline scripts on public pages), frame embedding refused, MIME sniffing disabled, referrer and browser-feature policies set. | In place | |
| Staff access | Every staff account must set up two-step sign-in (TOTP) before it can reach the admin panel; the secret is stored encrypted and recovery codes are hashed and single-use. | In place | |
| Approval record | Approvals are written to an append-only, hash-chained ledger that the database refuses to update or delete, and every chain head is copied to storage outside the database each hour so a change to the record can be detected. | In place | |
| Template provenance | Every published template version records its source and its reviewer; the reviewer cannot publish; a published version cannot be changed, only superseded. | In place | |
| Backups | Nightly database backups, encrypted, copied off the server, kept for 7 daily, 5 weekly and 12 monthly cycles; a backup that lacks the integrity rules is refused; a missed backup raises an alert. The backup job is written and tested; it is not yet running on the server. | Planned | |
| Restore drill | Restoring a backup into an isolated environment and verifying the approval record against its off-site anchors. | Planned | |
| Customer sign-in | Two-step sign-in for law-firm users. There are no customer accounts yet. | Planned | |
| Sub-processors | Backup storage and error reporting run on third-party services; the full list is published with the data-processing agreement. | Planned | |
| SOC 2 | No SOC 2 report exists and the audit has not started. We say so rather than show a badge. | Not started | |
| Penetration test | No external penetration test has been performed. | Not started | |
| HIPAA | No business associate agreement is offered. | Not offered |
Each "in place" row is backed by an automated test in our own code base that fails if the control is removed. Dates are when a person last re-read the row against that evidence.