MENTARA
Company

What we are entitled to display, and how we govern the rest.

Recognition and governance get conflated in supplier assessment. The certifications MENTARA does not hold, and the governance that operates regardless.

Two different questions

Supplier assessment asks two questions that sound related and are not. The first is what a supplier can display — certifications, partner tiers, awards, memberships, directory listings. The second is how the supplier actually governs its work. A firm can score well on the first and poorly on the second, which is why the first gets checked and the second is what determines how delivery goes.

MENTARA is new, so the answer to the first question is short, and it is given immediately below rather than assembled from inference further down the page. The rest of this page is the second question, which is where the substance is.

Security and data protection have their own page, in more depth than belongs here.

02

What we can display today.

State today

MENTARA holds no certifications: no ISO 27001, no SOC 2, no equivalent third-party attestation, and no audit in progress with an appointed auditor. We hold no badged partner status with Salesforce, Microsoft, ServiceNow, SAP or AWS, though we deliver on those platforms. There are no awards, no memberships presented as endorsement, and no client logos, because there is no published client work yet.

Each of those will appear here when it exists and is independently verifiable, with its scope and date attached. Where your procurement policy requires a certified or badged supplier as a precondition, that is worth establishing in the first conversation rather than the fifth — and two routes usually work: a contained engagement that does not touch production or regulated data, or MENTARA working under a certified prime.

Read the security position in full

Governance

Four domains, and what operates in each.

Described as practice rather than as certified control. None of it has been validated by an independent third party, and saying so plainly is itself part of the governance.

01Quality managementRepeatable delivery controls rather than a quality function that inspects work after it is finished. Scope, decision ownership and acceptance criteria are documented before an increment is built, reviews are sized to the risk of the change rather than applied uniformly, and corrective actions are tracked to closure rather than logged.
  • Document scope, acceptance criteria and decision ownership up front
  • Size review effort to the risk the change actually carries
  • Track lessons and corrective actions to closure
02Security and privacyLeast-privilege access, secure engineering practice, data minimisation and risk assessment proportionate to what the engagement genuinely touches. The full position — what is contractually committed in every engagement, and what remains uncertified — is set out on the trust page rather than summarised into something less useful here.
  • Apply least-privilege, time-bounded access
  • Limit collection and retention of personal data
  • Escalate security and privacy concerns before internal certainty
03Commercial and workforce governanceClear contracts, explicit responsibilities, and qualified jurisdiction-specific advice where it is required. Employment classification, tax treatment and contracting terms differ materially between India, the United States, the United Kingdom and Europe, and the Middle East — so they are handled per engagement rather than through a global template that is wrong somewhere.
  • Separate engagement and employment responsibilities in writing
  • Avoid compliance claims stated as if they were universal
  • Take qualified legal and tax advice rather than generalising
04Responsible technologySafety, fairness, explainability, accessibility and human oversight considered while a system is being designed, rather than assessed once it is built and expensive to change. This matters most in the AI and data work, where the failure modes are least visible to the people they affect.
  • Assess material risks and who bears them before building
  • Record the design decisions that constrain how a system behaves
  • Monitor operation for unintended effects, with a named owner
Responsible technology

Where the AI work needs a firmer line than a principle.

Most published governance language about artificial intelligence is written to be unobjectionable, which makes it useless for deciding anything. Two commitments are specific enough to be held to, so those are the two stated here.

The first is human oversight proportionate to consequence. Where a system's output affects a person's access to employment, credit, care or a public service, a human decision-maker must be able to see why the system produced that output, must hold the authority to override it, and must be expected to use that authority. Oversight that exists only to satisfy a policy is worse than none, because it distributes accountability without transferring it — the person named as the reviewer carries the responsibility for a decision they were never equipped to inspect.

The second is that we will say when a model is the wrong instrument. A significant proportion of what arrives scoped as an AI problem is a data quality problem, a process problem, or a decision nobody has yet been willing to make explicit. Naming that reduces the work we are engaged to do, which is precisely the point at which this commitment either operates or does not.

Where an engagement falls under a specific regime — the EU AI Act, sectoral regulation, or a client's own model-governance standard — the obligations are identified during scoping and written into the engagement, rather than treated as covered by a general assurance.

Standing rules

The rules governing what appears anywhere we publish.

These apply to this website, to proposals, to profiles, and to anything a MENTARA person writes on the firm's behalf.

The evidence gate itself — define the claim, collect the evidence, validate the facts and dates, secure written permission, then publish — is set out in full on the clients and proof page.

  • No certification, partner status or regulatory approval is stated without a current, verifiable credential behind it, published with its scope and date.
  • No prior-employer name is used in a way that implies an individual's institutional experience is MENTARA's track record.
  • Client, candidate and employee information is handled for defined and lawful purposes, and retained only as long as those purposes require.
  • Third-party services and subcontractors are assessed according to the risk they introduce, before adoption rather than after.
  • Incidents, complaints and control failures have documented response and escalation routes — including the ones that reflect badly on us.
  • Policies and controls are reviewed as the company, the services and the legal obligations change, on review dates that are real rather than nominal.
Procurement questions

The questions a supplier assessment will ask.

Are you ISO 27001 or SOC 2 certified?

No, and no audit is in progress with an appointed auditor. The intended path — a documented information-security management system, a recorded internal security assessment, then a decision on whether formal certification is useful — is described on the trust page and stated as intent rather than as a claim.

If certification is a hard precondition in your policy, it is better established now than after an evaluation cycle both sides have paid for.

Are you a Salesforce, Microsoft, ServiceNow, SAP or AWS partner?

No. We deliver on those platforms and describe that as capability, not as partner status, and we do not display vendor logos in a way that implies a tier we do not hold.

This is checkable in each vendor's public partner directory, and we would expect you to check it. Where a piece of work genuinely requires badged partner status — certain licensing arrangements, or vendor-specific support paths — that is a reason to involve a partner firm, and we will say so rather than work around it.

Who is accountable for data protection at MENTARA?

Accountability sits with the company's directors, and the individual accountable for data handling on your engagement is named in the proposal alongside the engagement lead.

We are a firm founded in July 2026 and do not have a separately appointed data protection officer. Where an engagement's jurisdiction or data categories require one, that is identified during scoping — including where the conclusion is that we are not the appropriate party to be holding the data at all.

Will you sign our supplier code of conduct and security schedule?

Usually, and we read them before signing rather than after. Where a clause commits us to something we do not currently have — a named certification, a control we cannot evidence, a response time we cannot staff — we raise it during review instead of signing and hoping it is never tested.

That occasionally adds a few days to a procurement cycle. It is preferable to a warranty we would breach.

How do you handle a subcontractor or partner firm on our engagement?

They are disclosed to you before they start, assessed against the risk they introduce, and bound to the obligations we hold on your engagement. We remain accountable to you for their work.

Where an obligation cannot be passed through to a third party, we tell you which one, and you decide whether the arrangement still works.

07

Governance is easier to check than to describe.

How to test this

The most efficient assessment of this page is to send your standard supplier questionnaire and security schedule early, then read what comes back for the answers that say no. A supplier returning a fully compliant response at our stage has either misunderstood the questions or is answering them optimistically.

The same test applies to anything we claim. Every externally visible claim has to clear one gate — define it, evidence it, validate it, secure permission, publish — and the gate is written down rather than described.

See how a claim gets published

Send the governance requirements your procurement team will apply.

Share the business context, constraints and expected outcome. MENTARA will identify the relevant accountable route.

One partner. One plan. Measurable outcomes.