Trust & security

Built to be trusted with privileged legal work.

Manda handles in-house legal teams' most sensitive work, so security is foundational, not a feature. Here is how we protect your data, and where our certification program stands today.

Handling privileged material

Requests reach Manda through a dedicated request channel by default. We do not read your mailbox. Uploads and integrations only receive the access you explicitly initiate and authorize, so confidentiality and privilege stay under your control.

How we protect your data

Tenant isolation

Tenant isolation is enforced by the database engine itself: row-level security policies on every tenant table restrict each request to your organization's rows, underneath the application's own scoping. Org identity comes from your authenticated session, never from request input.

Encryption

TLS 1.2+ in transit everywhere. Data is encrypted at rest in our database and private document store. The current invoice-import path retains structured invoice fields rather than the source PDF.

Least privilege & audit trail

Access follows least-privilege, and security-relevant events are written to an append-only audit trail the application can only add to.

AI governance

Your data is never used to train third-party or foundation models, and AI requests use zero-data-retention provider settings. Manda's own pricing and benchmarking intelligence is built only from de-identified, aggregated contributions, never from identifiable customer data. Estimates and scores show the evidence and assumptions behind them.

Data portability

Export your mandates and invoices at any time. No lock-in.

Vetted subprocessors

A short, deliberate list of infrastructure providers, each engaged under data-protection terms.

Certifications & frameworks

Our formal certification program is in progress. We don't claim certifications we haven't completed. We're glad to share our current controls and roadmap in detail under NDA.

SOC 2 Type II

Our SOC 2 Type II program is underway. We do not claim an attestation before it is complete.

Underway
ISO/IEC 42001

We are building our AI management system to the ISO/IEC 42001 standard.

In progress
NIST AI RMF

Our AI governance program is designed around the NIST AI Risk Management Framework.

Aligned to

Subprocessors

ProviderPurposeRegion
SupabasePostgres database and document storageCanada (ca-central-1)
VercelApplication hosting and AI gatewayUnited States (application compute region: Montréal, Canada)
ClerkAuthentication and organization managementUnited States
AnthropicAI model inference, via Vercel AI Gateway, zero retentionUnited States
Moonshot AIAI model inference (Kimi), via Vercel AI Gateway, zero retentionUnited States
OpenAIText embeddings for search and matching, via Vercel AI Gateway, zero retentionUnited States
ResendTransactional and inbound emailUnited States
SentryServer error monitoringUnited States
UpstashRate limiting (request metadata only)United States