Trust Centre

Your clients trust you.
You can trust us.

Enterprise-grade security, responsible AI governance, and transparent data practices — built into every layer of the platform.

Our Security Commitments

Security is not a feature — it is the foundation. Every control is implemented in code, verified by automated evidence collection, and reviewed quarterly.

End-to-End Encryption

All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Secrets are stored in isolated environment vaults, never committed to source control.

Row-Level Tenant Isolation

Every firm operates in complete data isolation enforced at the database level. Row-level security policies ensure no cross-tenant data leakage — architecturally impossible.

Zero-Retention AI Processing

All AI providers operate under zero-retention API agreements. No client data is stored by any AI provider after processing. Your data is never used for model training.

UK GDPR Compliant

Full compliance with UK GDPR and the Data Protection Act 2018. EU-hosted infrastructure, data processing agreements with all processors, and transparent processing records.

Access Controls & Audit Logging

Role-based access control with four permission tiers. Complete audit trails for every AI operation, document access, and configuration change.

EU-Hosted Infrastructure

All primary data processing and storage runs on EU-based infrastructure. Hosting, database, authentication, and file storage are all within EU regions.

Responsible AI Governance

Mmentum integrates AI to enhance — not replace — consultant expertise. Our AI governance framework ensures every operation is transparent, auditable, and privacy-preserving.

Human Oversight

High-cost or high-risk AI operations require human approval before execution. Automated gates ensure no significant action happens without review.

PII Protection

Personal data is automatically detected and masked before any AI processing. Multiple UK-specific data types are recognised and tokenised in real-time.

No Training on Your Data

All AI provider agreements explicitly prohibit training on input data. Processing is stateless — your prompts and documents leave no trace in AI systems.

Prompt Security

All AI inputs pass through a multi-layer security pipeline including injection detection, content boundary enforcement, and input sanitisation before reaching any model.

Full Audit Trail

Every AI operation is logged with the model used, resource consumption, and data sensitivity classification. No personal data values are ever stored in audit logs.

Output Validation

All AI-generated content is validated against strict schemas before being stored or displayed. Malformed output is gracefully handled — never silently accepted.

Data Protection

Your data is subject to strict handling policies at every stage of its lifecycle.

Data Residency

All primary data — database, authentication, and file storage — is hosted on EU-based infrastructure. AI processing uses stateless APIs with zero data retention, meaning no client data persists outside the EU.

Tenant Isolation

Every organisation operates within a completely isolated data boundary. Row-level security is enforced on every table in the database. Cross-tenant data access is architecturally impossible — not just policy-prohibited.

Data Lifecycle

You control your data lifecycle. All content can be permanently deleted at any time. When a subscription ends, a 90-day grace period allows data export, after which all data is automatically purged. Audit records are retained separately for compliance.

AI Data Handling

Personal data is automatically detected and masked before AI processing. Only the minimum context required is sent. All AI providers operate under zero-retention agreements — no prompts, documents, or responses are stored or used for training.

Your Rights

We support your full data rights under UK GDPR: access, rectification, erasure, portability, and objection. Data Subject Access Requests are responded to within 30 calendar days.

Compliance & Certifications

We align to industry-recognised frameworks and are actively pursuing formal certifications.

UK GDPR

Compliant

Registered with the ICO. Data processing agreements with all processors. EU-hosted infrastructure.

SOC 2 Type 2

In Progress

Controls implemented and operational. Formal audit observation period in progress.

UK Cyber Essentials

Aligned

Technical controls aligned to Cyber Essentials v3.3. Certification assessment planned.

AIUC-1

Compliant

AI-specific controls covering transparency, human oversight, data governance, and accountability.

Security Documentation

Detailed security documentation is available on request for prospective and existing clients under NDA.

System Security Plan

Complete system architecture, control matrix, and data flow documentation.

AI Governance Policy

Our responsible AI framework, model governance, and data handling practices.

Sub-Processor Register

Full list of third-party processors, their roles, and compliance certifications.

DPIA

Data Protection Impact Assessment for AI processing under UK GDPR.

To request documentation, contact info@mmentum.me

Responsible Disclosure

We welcome responsible security research. If you believe you have found a vulnerability, please report it to . We commit to acknowledging reports within 2 business days and will work with you to resolve issues promptly. info@mmentum.me.

Our full vulnerability disclosure policy is available on request.

Questions about security?

Our team is happy to walk through our security architecture and provide documentation under NDA.

Get in Touch