
Trust and Security
MindsetOS helps teams build psychological awareness and mindset mastery. We understand that this means people share personal reflections and insights with our platform. Protecting that data is fundamental to the trust our users place in us, and we treat that seriously.
| Measure | Detail |
|---|---|
| Encryption in transit | TLS 1.2+ on all connections |
| Encryption at rest | AES-256 encryption |
| Authentication | Secure session management via BetterAuth |
| Access control | Role-based access; least-privilege principle |
| Data hosting | EU/EEA primary hosting via Vercel and Convex |
| Certification | Cyber Essentials certified |
| Data protection compliance | UK GDPR, EU GDPR, Australian Privacy Act, CCPA compliant |
| AI model training | Your data is never used to train AI models |
MindsetOS complies with applicable data protection laws worldwide, including the UK GDPR, the EU GDPR, the Australian Privacy Act 1988, and US state privacy laws such as the CCPA. We are registered with the UK Information Commissioner’s Office (ICO).
Key privacy commitments:
MindsetOS uses AI to deliver personalised coaching at scale. Here’s how we keep that safe:
| Provider | Purpose | Data location and safeguards |
|---|---|---|
| Vercel | App hosting and content delivery | EU/EEA |
| Convex | Backend storage, access management and monitoring | EU/US (SCCs applied) |
| OpenAI and Anthropic | AI coaching language processing | UK/US (SCCs + IDTA applied; zero data retention) |
| Resend | Transactional email delivery | US (SCCs applied) |
| BetterAuth | User authentication and session management | Self-hosted (data remains within MindsetOS infrastructure) |
We understand that enterprise organisations need thorough due diligence. Here’s what we can provide:
If you have questions about our security practices or need documentation for your procurement process, contact us at admin@themindsetos.com.