Is this your company?Buyers are checking Mindstudio here. Claim mindstudio.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Mindstudio SOC 2 compliant?
Mindstudio is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Mindstudio GDPR compliant?
According to Mindstudio's public trust center, Mindstudio is GDPR compliant. On SOC2C this listing is Listed.
Is Mindstudio SOC 2 Type I or Type II?
Mindstudio is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Mindstudio's SOC 2 for a vendor risk assessment?
Yes. Mindstudio's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Mindstudio penetration tested?
Mindstudio hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Mindstudio secure?
Security isn't a single yes/no, but Mindstudio is SOC 2 Type II compliant and holds SOC 2 Type I, SOC 2 Type II, GDPR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Mindstudio have a bug bounty or vulnerability disclosure program?
Mindstudio hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@mindstudio.ai or via a /security page (Mindstudio lists a security contact).
Who are Mindstudio's subprocessors?
Mindstudio lists 18 subprocessors on its trust center, including Cloudflare, Ltd., Amazon Web Services, Zilliz Inc., Vercel Inc., Google Cloud Platform. Buyers use this for fourth-party risk review.
Where does Mindstudio host or store data?
Mindstudio hosts on AWS, GCP. Data residency details are on its trust center.
Where is Mindstudio's trust center or security page?
Mindstudio's trust center is at https://trust.mindstudio.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Are you compliant with any security standards?
MindStudio is committed to maintaining the highest standards of security and privacy. We are currently certified under SOC 2 Type I and Type II Security standards.
Who has access to the data sources used in an AI application?
Only authorized personnel within your workspace can access the data uploaded to an AI application, and all access is logged and monitored. Data sources used in building AI applications on MindStudio are vectorized and stored. No data from the data sources are used in AI training. MindStudio does not share data from data sources with third parties.
What kinds of user data types are uploaded to MindStudio?
There are four types of user data that can be uploaded to MindStudio: - Account Info: Email, username, profile picture, workspace name, and billing information. - Data Sources: Files that are uploaded when building a MindStudio application. Data sources are uploaded by the creator of an AI application when utilizing Retrieval Augmented Generation (RAG) in an application. - Runtime logs: These logs include system performance data, error reports, and usage statistics that help us monitor and improve the performance of the MindStudio platform. They do not contain any personally identifiable information. - AI user data: Data collected from the end user by the AI application. This includes any files uploaded to or information entered into the AI application by the end user, such as text inputs, images, or other documents.
Who has access to my account info?
Access to your account information is limited to authorized personnel within MindStudio who need it to provide support and maintain the platform. This includes the MindStudio customer support and billing teams. All access is logged and monitored to ensure your data is handled securely and in compliance with our Privacy Policy. MindStudio does not share your account information with third parties.
Who has access to AI user data?
AI user data is only accessible by the end user of an AI application. The creator of an AI application may enable logging within an AI application to collect AI user data for their own purposes. The creator of the AI application will not be able to view any user information without that user’s knowledge and consent. AI user data is not used for training AI models. MindStudio does not share AI user data with third parties.
Who has access to runtime logs on the MindStudio platform?
Access to runtime logs is limited to authorized personnel within MindStudio who need this information to maintain and improve MindStudio services. This includes the product and development teams. Runtime logs are not used for training AI models. MindStudio does not share runtime logs with third parties.
Where are MindStudio servers?
All servers are based in the United States, and our cloud service provider is Amazon Web Services (AWS).
What if my application needs to comply with a specific standard?
MindStudio offers a flexible platform for building AI applications. We do not develop or maintain any LLMs. Users building applications and using AI models are responsible for complying with local regulations and other relevant policies. We will regularly update our website and this resource with any additional updates.
How do you handle data breaches?
In the unlikely event of a data breach, we have a comprehensive incident response plan in place. This includes immediate containment and assessment of the breach, notification to affected users, and measures to mitigate any potential damage. Any interruptions in our operations are communicated via status.mindstudio.ai.
Is any data used to train AI models?
MindStudio leverages third-party providers such as OpenAI and Anthropic under enterprise/commercial API licenses. These providers state that data sent/received is not to be used for training their models. Please read more here: https://openai.com/enterprise-privacy https://console.anthropic.com/legal/terms - see Commercial Terms of Service Please review the MindStudio Terms of Use and Privacy Policy for more information.
How is data stored on MindStudio servers?
All data uploaded to MindStudio is stored encrypted on secure servers and is encrypted in transit. MindStudio uses industry-standard AES-256 encryption to protect your data while it is stored, and TLS 1.2 or higher for data transmitted.
What are your policies on data retention and deletion?
We retain data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. You can request the deletion of your data at any time, and we will ensure that it is securely and permanently removed from MindStudio systems.