Trust & Security

What we hold, how we handle it, and what we have not yet certified.

The security and data-handling position of a firm founded in July 2026 — stated plainly, including the attestations we do not hold, so your security review can start from facts rather than from a questionnaire response.

Read this before the questionnaire

Security review is usually the point where a new supplier gets quietly eliminated, and often for the right reasons. This page exists so that happens early and on accurate information, rather than after six weeks of evaluation.

Everything below distinguishes between what is true today, what is committed contractually in an engagement, and what is intended but not yet in place. Those three things are frequently blurred in supplier documentation. They are not blurred here.

02

Our certification position.

State today

MENTARA does not hold ISO 27001, SOC 2, or any equivalent third-party security attestation. No certification audit has been completed, and none is in progress with an appointed auditor.

Where your procurement policy requires a certified supplier as a precondition, that is worth establishing in the first conversation rather than the fifth. Two routes usually work: a contained engagement that does not touch production or regulated data, or MENTARA working under a certified prime.

Engagement controls

What is committed contractually in every engagement.

These are terms we sign up to, which means they are enforceable against us regardless of what any certificate would or would not say.

01Least-privilege access, time-boundedAccess is requested per person and per system, scoped to what the work requires, and revoked on a defined date rather than when someone remembers. We ask you to audit our access — and to tell us when we have more than we need.
02Your systems, your identity providerWe work inside your access-control regime rather than asking for credentials to be handed over. No shared accounts, no long-lived credentials in our own tooling, no exceptions requested for convenience.
03Data minimisation by defaultWe do not request production data where synthetic or masked data will do, and we say so when a request for real data is unnecessary. Where production access is genuinely required, it is scoped, logged and time-limited.
04Named individuals, disclosedYou know exactly which individuals hold access to your environment at any point. Additions require your approval; departures trigger revocation the same day.
05Incident notification with a clockIf we become aware of a security incident affecting your data or systems, we notify you without undue delay and within the period agreed in the engagement — not after we have finished investigating internally.
06Return and deletion on exitAt the end of an engagement, your data and artefacts are returned in a usable form and our copies deleted, with written confirmation. This is defined at mobilisation, not negotiated at the end.
Data protection

Working across several regulatory regimes at once.

MENTARA works across India, the United States, the United Kingdom and Europe, and the Middle East and wider Asia-Pacific, so an engagement may fall under any of several regulatory regimes. These differ in ways that matter operationally rather than only legally, so we treat data protection as engagement-specific rather than as a single global policy statement.

In practice this means establishing four things during scoping, before any access is granted: which categories of personal or regulated data the work will touch; which jurisdictions the data subjects and the processing sit in; whether any transfer outside those jurisdictions is required and on what legal basis; and who is controller and who is processor for each dataset involved.

MENTARA is registered in India and subject to the Digital Personal Data Protection Act. Where an engagement involves UK or EU personal data, the applicable UK GDPR or GDPR obligations are addressed through the engagement's data-processing terms, including transfer mechanisms. Where it involves US healthcare or financial data, the specific regime is identified in scoping rather than assumed to be covered by a general clause.

We will not accept regulated data into an engagement on the basis of a general assurance. If the scoping conversation cannot establish the four points above, that is a signal the engagement is not ready to start.

Internal practice

How MENTARA runs itself.

Described as practice, not as certified control. The distinction is deliberate: none of this has been audited by an independent third party.

A firm of our size should be honest that these are operating practices maintained by a small team, not a control environment validated by an auditor. They are the practices we would want a supplier of ours to have.

  • Multi-factor authentication on all company accounts and services, without exception for convenience.
  • Company devices with full-disk encryption, automatic screen lock and managed updates.
  • Secrets and credentials held in a dedicated secret manager, never in source control, documents or messages.
  • Source control with mandatory review before merge, and no direct commits to protected branches.
  • Dependency and vulnerability scanning in the build pipeline, with findings triaged rather than accumulated.
  • A maintained record of every third-party service that could process client data, reviewed before adoption rather than after.
  • Access review whenever someone joins, changes role or leaves — and on a scheduled cadence regardless.
Intent

What we are working toward, stated as intent.

Included because you will ask, and because a supplier who cannot describe their trajectory is telling you something. None of this is complete, and none of it should be treated as a claim.

  1. 01 Documented ISMS

    A written information-security management system covering policy, asset inventory, risk assessment and review cadence — the prerequisite for any certification path, and worth having on its own merits.

  2. 02 Independent assessment

    Third-party review of that system before pursuing formal certification, on the basis that an assessment we might fail is more useful than one designed to be passed.

  3. 03 Formal certification

    ISO 27001 or SOC 2 Type II, sequenced according to which is actually being asked for in evaluations. We will publish the certificate and its scope when it exists, and nothing before then.

  4. 04 Continuous evidence

    Control evidence generated as a by-product of how we work rather than assembled ahead of an audit window.

Security review

The questions your security team will ask.

Will you complete our security questionnaire?

Yes, and we will answer it accurately, including the answers that count against us. Where the honest answer is “no” or “not yet”, that is what the response will say rather than a description engineered to read as compliant.

If a “no” on a mandatory item disqualifies us, we would rather establish that at questionnaire stage than consume more of your team's time.

Where is our data processed and stored?

Wherever the engagement specifies, agreed before work starts. Our strong default is that client data stays in the client's own environment and jurisdiction, and that MENTARA works inside it rather than extracting data into our systems.

Where something must be processed outside your environment, it is identified specifically during scoping — what, why, where, for how long, and under what legal transfer basis.

Do you use subcontractors or offshore delivery?

Any individual working on your engagement is disclosed to you by name, along with their employment relationship to MENTARA and their location. You approve who has access to your environment.

We do not subcontract work to undisclosed third parties, and we do not move work to a location you have not agreed to.

Do you use AI tools on client work?

Only under terms agreed with you in advance, and never with client code, data or confidential material submitted to a service that trains on submitted content.

Where AI-assisted development is used, it is disclosed, the tooling is named, and the same review standards apply to that output as to anything else. If your policy prohibits it, we work without it and say so honestly rather than quietly continuing.

What insurance do you carry?

Cover is confirmed in writing during contracting, with the specific policies and limits stated. We do not publish them here, because insurance requirements differ substantially by client, engagement type and jurisdiction, and a general figure would be of no use to your risk team.

How do we report a security concern?

Email sales@mentaraglobal.com with “Security” in the subject line and we will route it to the accountable owner. If you are reporting a suspected vulnerability in this website or in something we have built for you, we will confirm receipt and tell you who is handling it.

We will not pursue anyone who reports a genuine security issue to us in good faith.

Send the security questionnaire early rather than late.

Share the business context, constraints and expected outcome. MENTARA will identify the relevant accountable route.

One partner. One plan. Measurable outcomes.