AICPA CC6.1–CC8.1 & ISO 27001 Aligned
Security, compliance, & data privacy engineered into every single layer.
Enterprise resource planning demands uncompromising governance. Explore how Mints Global safeguards your operational records, enforces 5-tier role clearance, and complies with international privacy laws.
Six Pillars of Enterprise Defense
Engineered by cybersecurity and software specialists at Mints Global in Dubai, UAE.
SOC 2 Type I Readiness & ISO 27001 ISMS
Our Information Security Management System aligns with AICPA SOC 2 2017 Trust Services Criteria (Security & Confidentiality) and ISO/IEC 27001:2022 standards, governing all access reviews, vulnerability gates, and data protection lifecycles.
5-Tier RBAC & Edge Session Guard
Access control is enforced at both the Next.js Edge proxy and Google Cloud Firestore database rules. Cryptographic HttpOnly session cookies prevent privilege escalation and token tampering.
API Rate Limiting & Enterprise CSP Headers
Sliding-window rate limiters defend all API endpoints against credential stuffing and abuse. Strict HTTP headers enforce Content-Security-Policy, HSTS, X-Frame-Options, and XSS filtering.
Bank-Grade Encryption & Web Crypto
All Customer Data is encrypted at rest via AES-256 and in transit via TLS 1.3. Cryptographic passwords and key lifecycles are generated using high-entropy Web Crypto (crypto.getRandomValues).
Immutable Administrative Audit Trail
Every privileged event—including role modifications, salary disbursements, and access reviews—is logged to an append-only, tamper-evident audit store with structured metadata.
Formula & Injection Sanitization
Exported CSV spreadsheets are automatically neutralized against formula injection, outbound webhook URLs undergo strict SSRF regex validation, and user HTML is parsed via strict DOM allowlists.
Common Criteria (CC) Technical Remediation
Verified technical controls enforcing database security, anti-injection safeguards, and secure SDLC.
5-Tier RBAC Matrix & Quarterly Access Reviews
Scoped employee access in firestore.rules with 1-click in-app access review console and audit log sign-off.
Cryptographic HttpOnly Cookies & Progressive Lockout
Edge proxy validates secure session tokens; exponential client lockout mitigates brute-force attacks.
Fail-Closed API Handlers & URL Allowlisting
Strict authentication on all API routes; outbound Discord webhook destinations validated against strict regex.
CSV Formula Neutralization & DOM HTML Sanitizer
All CSV exports prepend apostrophes on formula characters (=, +, -, @); announcements sanitized against XSS.
Sliding-Window Rate Limiter & Real-Time Console
Per-IP sliding window across all /api/* routes; instant anomaly alerts routed to dedicated operations webhooks.
Automated Security Audit & Type Check CI Gate
GitHub Actions CI pipeline enforces ESLint, zero-error TypeScript check, npm audit, and Next.js build verification.
Approved Cloud Infrastructure Registry
Customer Data is stored in secure regional Google Cloud and Vercel edge nodes governed by active Data Processing Addendums (DPAs).
| Vendor & Provider | Functional Scope | Data Storage Regions | Security Certifications |
|---|---|---|---|
| Google Cloud Platform / Firebase | Firestore Database, Auth, Cloud Storage, Serverless Functions | Europe (Frankfurt, Belgium), UK (London), India (Mumbai), US (Iowa) | SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018 |
| Vercel Inc. | Edge Compute, Next.js Serverless Hosting & Anycast CDN | Global Edge Network (300+ Anycast PoPs worldwide) | SOC 2 Type II, ISO 27001 |
| OpenAI LLC | Receipt & Invoice OCR Vision API (Zero-Day Data Retention) | US Multi-Region (Ephemeral text extraction only) | SOC 2 Type II |
| Discord Inc. (Customer Configured) | Operational Telemetry & System Event Alert Webhooks | United States (Non-PII event broadcasts only) | ISO 27001 Aligned |
SOC 2 & ISO 27001 Readiness
We operate with complete commercial honesty: our technical controls are aligned with SOC 2 Type I/II Common Criteria and ISO/IEC 27001:2022 standards.
Formal third-party audit readiness crosswalk is complete with quarterly access review workflows, incident tabletop playbooks, and automated CI/CD security gates.
Uptime SLA & Incident Disclosure
We commit to 99.9% uptime across standard tiers, and 99.95% financially-backed SLA for Enterprise accounts with 24/7 priority incident response.
To report a suspected security vulnerability under our responsible disclosure program, refer to our RFC 9116 security file at /.well-known/security.txt or email info@mintsglobal.ae.
Replace disconnected software with one command center.
Join ambitious teams that have unified their operations into a single, secure, role-based platform.