Skip to content

Security

Your prompts are your data

Cloudmind never trains on customer data, supports client-side redaction before anything leaves your process, and can run entirely inside your own network.

Controls

  • SOC 2 Type II

    Audited annually. Report available under NDA from your account team.

  • Encryption

    TLS 1.3 in transit, AES-256 at rest, with per-tenant key separation on Enterprise.

  • Client-side redaction

    Register a redaction function and PII is stripped in your process before any network call.

  • Data residency

    Pin storage to US, EU or AU regions. Data does not leave the region you choose.

  • No training on your data

    Contractually committed. Customer prompts and completions are never used to train models.

  • Self-hosted

    Run the full stack in your VPC. No trace data crosses your network boundary.

Reporting a vulnerability

Email security@cloudmind.example with a description and reproduction steps. We acknowledge within one business day and aim to triage within three.

We do not currently run a paid bounty, but we credit reporters in our advisories unless you would rather stay anonymous.

Please do not test against other customers' data or run automated scanning against production. If you need an environment to test in, ask and we will provision one.

Frequently asked questions

Do you train models on customer data?
No, and this is a contractual commitment rather than a policy statement. Customer prompts and completions are used only to render the product for that customer.
Where is data stored?
By default, US regions on AWS. Scale and Enterprise plans can pin storage to EU (Frankfurt) or AU (Sydney). Self-hosted deployments store everything in your own infrastructure.
How do I get your security package?
Email security@cloudmind.example. The package includes the SOC 2 Type II report, most recent penetration test summary, subprocessor list, DPA and a completed CAIQ, all under NDA.