v1.6.0SOC 2 Remediation, Theme Contrast & Mobile Navigation now live across Mints ERP.
Home/Trust & Security Center
SOC 2 Type IReady

AICPA CC6.1–CC8.1 & ISO 27001 Aligned

Enterprise Trust Center99.95% Enterprise SLA

Security, compliance, & data privacy engineered into every single layer.

Enterprise resource planning demands uncompromising governance. Explore how Mints Global safeguards your operational records, enforces 5-tier role clearance, and complies with international privacy laws.

Architecture Safeguards

Six Pillars of Enterprise Defense

Engineered by cybersecurity and software specialists at Mints Global in Dubai, UAE.

SOC 2 & ISO 27001 Aligned

SOC 2 Type I Readiness & ISO 27001 ISMS

Our Information Security Management System aligns with AICPA SOC 2 2017 Trust Services Criteria (Security & Confidentiality) and ISO/IEC 27001:2022 standards, governing all access reviews, vulnerability gates, and data protection lifecycles.

Zero-Trust Clearance

5-Tier RBAC & Edge Session Guard

Access control is enforced at both the Next.js Edge proxy and Google Cloud Firestore database rules. Cryptographic HttpOnly session cookies prevent privilege escalation and token tampering.

Boundary & DoS Defense

API Rate Limiting & Enterprise CSP Headers

Sliding-window rate limiters defend all API endpoints against credential stuffing and abuse. Strict HTTP headers enforce Content-Security-Policy, HSTS, X-Frame-Options, and XSS filtering.

AES-256 & Web Crypto

Bank-Grade Encryption & Web Crypto

All Customer Data is encrypted at rest via AES-256 and in transit via TLS 1.3. Cryptographic passwords and key lifecycles are generated using high-entropy Web Crypto (crypto.getRandomValues).

Immutable Audit Log

Immutable Administrative Audit Trail

Every privileged event—including role modifications, salary disbursements, and access reviews—is logged to an append-only, tamper-evident audit store with structured metadata.

Defensive Coding Standards

Formula & Injection Sanitization

Exported CSV spreadsheets are automatically neutralized against formula injection, outbound webhook URLs undergo strict SSRF regex validation, and user HTML is parsed via strict DOM allowlists.

SOC 2 Trust Services Criteria

Common Criteria (CC) Technical Remediation

Verified technical controls enforcing database security, anti-injection safeguards, and secure SDLC.

CC6.1 Logical Access Controls

5-Tier RBAC Matrix & Quarterly Access Reviews

Scoped employee access in firestore.rules with 1-click in-app access review console and audit log sign-off.

CC6.3 Authentication & Session Security

Cryptographic HttpOnly Cookies & Progressive Lockout

Edge proxy validates secure session tokens; exponential client lockout mitigates brute-force attacks.

CC6.6 Boundary Protection & Anti-SSRF

Fail-Closed API Handlers & URL Allowlisting

Strict authentication on all API routes; outbound Discord webhook destinations validated against strict regex.

CC6.7 Injection & Input Sanitization

CSV Formula Neutralization & DOM HTML Sanitizer

All CSV exports prepend apostrophes on formula characters (=, +, -, @); announcements sanitized against XSS.

CC7.2 Rate Limiting & Telemetry Alerts

Sliding-Window Rate Limiter & Real-Time Console

Per-IP sliding window across all /api/* routes; instant anomaly alerts routed to dedicated operations webhooks.

CC8.1 Change Management & CI/CD Gate

Automated Security Audit & Type Check CI Gate

GitHub Actions CI pipeline enforces ESLint, zero-error TypeScript check, npm audit, and Next.js build verification.

Data Sovereignty & Subprocessors

Approved Cloud Infrastructure Registry

Customer Data is stored in secure regional Google Cloud and Vercel edge nodes governed by active Data Processing Addendums (DPAs).

Vendor & ProviderFunctional ScopeData Storage RegionsSecurity Certifications
Google Cloud Platform / FirebaseFirestore Database, Auth, Cloud Storage, Serverless FunctionsEurope (Frankfurt, Belgium), UK (London), India (Mumbai), US (Iowa)SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018
Vercel Inc.Edge Compute, Next.js Serverless Hosting & Anycast CDNGlobal Edge Network (300+ Anycast PoPs worldwide)SOC 2 Type II, ISO 27001
OpenAI LLCReceipt & Invoice OCR Vision API (Zero-Day Data Retention)US Multi-Region (Ephemeral text extraction only)SOC 2 Type II
Discord Inc. (Customer Configured)Operational Telemetry & System Event Alert WebhooksUnited States (Non-PII event broadcasts only)ISO 27001 Aligned
Honest Transparency

SOC 2 & ISO 27001 Readiness

We operate with complete commercial honesty: our technical controls are aligned with SOC 2 Type I/II Common Criteria and ISO/IEC 27001:2022 standards.

Formal third-party audit readiness crosswalk is complete with quarterly access review workflows, incident tabletop playbooks, and automated CI/CD security gates.

Service Reliability

Uptime SLA & Incident Disclosure

We commit to 99.9% uptime across standard tiers, and 99.95% financially-backed SLA for Enterprise accounts with 24/7 priority incident response.

To report a suspected security vulnerability under our responsible disclosure program, refer to our RFC 9116 security file at /.well-known/security.txt or email info@mintsglobal.ae.

Scale with Confidence

Replace disconnected software with one command center.

Join ambitious teams that have unified their operations into a single, secure, role-based platform.