Trust & Security
Security & trust at Mitravan.
Last updated May 2026
We sell trust software, so we hold ourselves to the same standard we help our customers meet. Here is how Mitravan handles your data - and, honestly, what is done versus what is still in progress.
How we handle your data
- Human approval, always
- Every AI-generated answer is reviewed and approved by your team before it ships. Autonomous publication is never on the roadmap.
- Your data is not used to train models
- We do not train foundation models on your content. Anthropic enterprise zero-retention terms apply to model processing.
- Data residency you choose
- Pick India (Mumbai), the EU (Frankfurt), or the US (Virginia) at signup. No silent migration afterwards.
- Least-privilege integrations
- Connections (Slack, Okta, GitHub, cloud) use scoped, revocable access - only what discovery and answering require.
- Citations & audit trail
- Every answer links to its source evidence, and changes are versioned in your rolling answer library.
Certifications & frameworks
| Standard | Status | Notes |
|---|---|---|
| SOC 2 Type II | In progress | Target completion H2 2026. |
| ISO 27001 | In scope | Planned for 2027. |
| DPDP (India) | Supported | Framework mapping + optional DPDP DPO-as-Service. |
| EU AI Act / ISO 42001 / NIST AI RMF | Mapped | Control mappings maintained and reusable across frameworks. |
Status reflects our roadmap as of the date above; we update this page as milestones complete. Ask us for current attestations.
Reporting & contact
For security questions, a DPA, sub-processor list, or to report a vulnerability, email hello@mitravan.ai. We respond to security reports promptly and will keep you updated until resolution.
Questions about our security?
Book a 15-minute call and we’ll walk through data handling, residency, and our compliance roadmap.
Book a 15-min call