Skip to content

Security & compliance

Your users' data,
handled like it's ours to lose

Analytics means holding data about people who never signed up with us. That asymmetry sets the bar: storage in one named place, no resale, no shadow copies, and an export button that always works.

Posture

verified today
Data residency
AWS, United States
Encryption at rest
AES-256
In transit
TLS 1.3
Breach notice
Within 72h

One place, and we name it

Events land in AWS in the United States and stay there. No analytics-on-your-analytics, no third-party ad pixels anywhere in the product, and no copies anywhere we haven't told you about.

Least access, always logged

Production access is scoped, time-boxed and behind hardware keys. Every administrative read of customer data writes an audit entry you can request.

Leaving is a feature

Full export on every plan, including the free one. Delete a project and its events are gone from primaries immediately, backups within 30 days.

Compliance

Where we actually stand

We're a young company. Rather than imply certifications we don't hold, here's the honest status of each.

GDPR

DPA available on request. You are the controller, we are your processor, and we share our current sub-processor list on request.

In place

No cloaking

The script behaves identically for real users, crawlers and ad-network scanners. It never goes quiet to evade inspection — and there's a test in CI that fails if it ever does.

In place

SOC 2 Type II

Controls are being documented now; the observation window opens once we have the headcount to staff it. We'll date it publicly.

Planned

Independent pen test

First external test scheduled before general availability. Summary report shared with customers under NDA.

Planned

If a certification is a hard requirement for you today, tell us — we'd rather say "not yet" than sell you a promise.

Practices

The unglamorous parts

Most breaches aren't clever. They're an old dependency, a shared password, a backup nobody tested. These are the habits that prevent the boring failures.

Found something? security@mintance.com. We reply within one business day and won't send lawyers after good-faith research.

Deploys
Reviewed, tested and reversible. No direct writes to production data, ever.
Dependencies
Automated advisories, patched on a clock — critical within 24 hours, high within a week.
Backups
Encrypted, held in the same US region as production, and restored into a scratch environment monthly so we know they work.
Accounts
SSO and 2FA on everything internal. Offboarding revokes access the same day.
Isolation
Every query is scoped to a project at the storage layer, not just in the UI.
Incidents
One on-call rotation, a written runbook, and a public post-mortem for anything customer-visible.

Sending us a security questionnaire?

Send it over — a real person answers it, usually the one who wrote the code in question. We'll also share our sub-processor list, DPA and architecture notes. General questions still go to hello@mintance.com.

security@mintance.com