Trust

What protects your data today, with the date each row was last checked — and what is not in place yet. Nothing on this page is a certification.

Each firm's documents and client answers live in that firm's own space. Our staff can see counts, hashes and status — never the content of a document or an answer — and every approval and every staff access grant is written to a ledger the firm can verify.

Area Control Status Last checked
Data location Today the application, its database and all stored data run in Mandatum's own containers on a shared server in India. Dedicated hosting in the United States, or in the firm's own country, has not been started. Not started
Dedicated infrastructure Mandatum runs in its own containers, with its own database and its own network, on a server that also hosts other businesses. A server used by Mandatum alone has not been started. Not started
Client data encryption Every client answer, draft and generated document is sealed under a key that belongs to that one matter; erasing the matter destroys the key. The database volume beneath is not encrypted as a whole. In place
Disk encryption Encryption of the database volume and backups at rest on the server. Not started
AI and client data No client document and no client answer is sent to any AI model. Every model call passes one checkpoint that refuses client data; the only provider connected today returns fixed text; a firm can switch AI off for its workspace. In place
Vulnerability reporting A published address for reporting a security problem (security.txt), with an acknowledgement. Planned
Card payments No card details are taken or stored; there is no payment form. Card-industry (PCI) scope does not apply today. Not offered
Transport All traffic over TLS on the canonical host; HTTP Strict Transport Security for one year, including subdomains. In place
Browser protections A strict Content Security Policy (per-request nonces, no inline scripts on public pages), frame embedding refused, MIME sniffing disabled, referrer and browser-feature policies set. In place
Staff access Every staff account must set up two-step sign-in (TOTP) before it can reach the admin panel; the secret is stored encrypted and recovery codes are hashed and single-use. In place
Approval record Approvals are written to an append-only, hash-chained ledger that the database refuses to update or delete, and every chain head is copied to storage outside the database each hour so a change to the record can be detected. In place
Template provenance Every published template version records its source and its reviewer; the reviewer cannot publish; a published version cannot be changed, only superseded. In place
Backups Nightly database backups, encrypted, copied off the server, kept for 7 daily, 5 weekly and 12 monthly cycles; a backup that lacks the integrity rules is refused; a missed backup raises an alert. The backup job is written and tested; it is not yet running on the server. Planned
Restore drill Restoring a backup into an isolated environment and verifying the approval record against its off-site anchors. Planned
Customer sign-in Two-step sign-in for law-firm users. There are no customer accounts yet. Planned
Sub-processors Backup storage and error reporting run on third-party services; the full list is published with the data-processing agreement. Planned
SOC 2 No SOC 2 report exists and the audit has not started. We say so rather than show a badge. Not started
Penetration test No external penetration test has been performed. Not started
HIPAA No business associate agreement is offered. Not offered

Each "in place" row is backed by an automated test in our own code base that fails if the control is removed. Dates are when a person last re-read the row against that evidence.