Enterprise-Grade Data Security
Your data is protected by SOC 2 Type II compliance, military-grade encryption, and comprehensive security controls trusted by enterprises worldwide.
Independently audited and certified for security, availability, and confidentiality
Comprehensive Security Framework
Our multi-layered security approach ensures your data remains protected at every level of our platform and infrastructure.
SOC 2 Type II Certified
Independently audited and certified for security, availability, and confidentiality controls
Enterprise-Grade Encryption
AES-256 encryption at rest and TLS 1.3 encryption in transit for all data
24/7 Security Monitoring
Continuous threat detection, anomaly monitoring, and real-time security alerts
Zero Trust Architecture
Role-based access controls with multi-factor authentication and least privilege principles
ISO 27001 Infrastructure
Data centers certified for international information security management standards
Regular Security Audits
Third-party penetration testing and vulnerability assessments on a regular basis
SOC 2 Type II Compliance
We adhere to the highest standards of the Trust Services Criteria
Security
Protection against unauthorized access through comprehensive access controls, encryption, and network security measures.
Availability
Systems are available for operation and use as committed, with 99.9% uptime SLA and robust disaster recovery procedures.
Processing Integrity
Data processing is complete, valid, accurate, timely, and authorized through automated controls and validation.
Confidentiality
Information designated as confidential is protected through encryption, access controls, and data classification policies.
Privacy
Personal information is collected, used, retained, disclosed, and disposed in accordance with recognized privacy principles.
Annual Audits
Independent third-party audits ensure ongoing compliance and continuous improvement of our security posture.
Regulatory Compliance
We maintain compliance with international data protection and security standards
SOC 2 Type II
CertifiedService Organization Control 2 with annual audits
ISO 27001
CompliantInformation Security Management System certification
GDPR
CompliantEuropean Union General Data Protection Regulation
CCPA
CompliantCalifornia Consumer Privacy Act requirements
DPDP Act
CompliantIndian Digital Personal Data Protection Act 2023
HIPAA Ready
AvailableHealthcare data protection controls available for eligible customers
Infrastructure & Encryption
Secure Cloud Infrastructure
Data stored in ISO 27001-certified cloud environments with global redundancy
Military-Grade Encryption
AES-256 encryption at rest and TLS 1.3 encryption in transit for all data
Role-Based Access Controls
RBAC ensures only authorized personnel can access sensitive systems
Continuous Monitoring
24/7 monitoring with audit trails, logging, and anomaly detection
Enterprises can align Mimasa AI deployment with their existing infrastructure, access-control and security practices. Organisations operating Cisco environments can learn how to deploy Mimasa AI on Cisco enterprise infrastructure while retaining familiar governance and operational controls.
Security Metrics
AI & Third-Party LLM Security
Our platform integrates with third-party Large Language Models (Claude, OpenAI, Mistral, Qwen, DeepSeek, etc.) to provide advanced analytics and insights. Here's how we ensure security:
Our Security Measures
- • Data minimization - only necessary information is transmitted
- • Encrypted data transmission to all LLM providers
- • No permanent storage of data with third-party providers
- • Regular security assessments of LLM integrations
- • User control over AI feature usage and data sharing
Important Considerations
- • We do not own or control third-party LLM providers
- • Each provider has their own security and privacy policies
- • Users should review provider policies before using AI features
- • Sensitive data should be carefully considered before AI processing
- • Enterprise customers have additional control options
Shared Responsibility Model
Security is a partnership. Here's how we work together to keep your data safe.
Our Responsibility
- • Infrastructure security and SOC 2 compliance
- • Data encryption in transit and at rest
- • Network security and access controls
- • 24/7 security monitoring and incident response
- • Regular security audits and vulnerability assessments
- • Employee security training and background checks
- • Backup and disaster recovery procedures
- • Compliance with data protection regulations
Your Responsibility
- • Maintaining secure account credentials and MFA
- • Ensuring uploaded data complies with applicable laws
- • Reviewing third-party LLM provider policies
- • Avoiding upload of sensitive PII without proper controls
- • Proper user access management within your organization
- • Regular review of shared dashboards and permissions
- • Reporting suspected security incidents promptly
- • Following data classification and handling guidelines
24/7 Incident Response
Detection
Real-time threat detection with automated alerts and monitoring systems
Response
Immediate incident response team activation with containment procedures
Recovery
Systematic recovery with post-incident analysis and improvement measures
Breach Notification: In the unlikely event of a security incident, we follow formal breach notification procedures in compliance with global privacy regulations, including timely notification to affected users and relevant authorities.
Data Security Questions
How Security Is Built Into the Platform, Not Added On
Security in an AI-powered analytics platform has to cover more ground than traditional software, because data does not just sit in a database — it also flows through connectors, transformation pipelines, and increasingly through large language models used to power conversational analytics and agentic workflows. Mimasa AI's approach is to treat every one of those stages as part of the governed workspace, rather than bolting security controls on around the edges of the product after the fact.
That governed workspace is where role-based access control, encryption, and audit logging live, and it is what lets a single deployment safely serve multiple teams with different access needs — finance seeing margin data that operations should not, for example, without needing entirely separate installations. Because the platform is LLM-agnostic, your organization can also choose which model providers are permitted for which workloads, which matters most for teams handling regulated or sensitive categories of data.
Deployment flexibility is the other half of the picture. Some organizations, particularly in the public sector or regulated industries, need data to remain on-prem or inside a private VPC they control end to end, while others are comfortable with a fully managed cloud deployment. Mimasa AI supports all three, so security architecture decisions can be made based on your organization's actual risk posture rather than being forced by a vendor's infrastructure limitations.
Questions About Our Security?
Our security team is available to answer questions about our practices, compliance certifications, or to discuss enterprise security requirements.
Office Address:
Xaigi Technology Pvt Ltd
A-130, Sector 63, Noida, Uttar Pradesh 201301, India
