Security and compliance, traceable to source.
Vantage is built and hosted on MindStudio, a SOC 2 Type I and Type II certified platform. Every control below is monitored continuously and evidenced on request.
SOC 2 reports issued for MindStudio, the certified platform Vantage runs on. Last reviewed 06 / 2026.
Built on certified infrastructure.
Vantage runs entirely on MindStudio, a platform that holds SOC 2 Type I and Type II certification. Hosting, encryption, network security, and infrastructure monitoring are inherited from that certified foundation, audited continuously by an independent firm.
On top of that foundation, Vantage adds its own application-layer controls: per-tenant isolation, method-level access control, and an append-only audit log of every read and write.
Where each framework stands.
An honest, two-layer view: certifications inherited from the MindStudio platform, alongside the frameworks Vantage is pursuing at the application layer.
What we monitor, continuously.
Thirty-six controls across six domains, monitored continuously through the certified platform. This is a representative summary; the full control matrix is available with the SOC 2 report.
36 CONTROLS · 6 DOMAINS · CONTINUOUSLY MONITORED · LAST SYNC 06 / 2026
- Encryption at rest (AES-256)
- TLS 1.3 in transit
- Network segmentation
- DDoS protection
- Continuous infrastructure monitoring
- Automated backups, point-in-time recovery
- Security policies reviewed annually
- Personnel background checks
- Security awareness training
- Incident response plan
- Vendor risk management
- Defined access roles
- Secure development lifecycle
- Code review on every change
- Dependency vulnerability scanning
- Annual penetration testing
- Per-action audit logging
- Idempotency and retry safety
- Role-based access control
- Per-tenant isolation
- Passwordless authentication
- Least-privilege enforcement
- Quarterly access reviews
- Customer-managed provisioning
- Inference-only AI, no model training
- No sale of customer data
- Customer-controlled deletion in 30 days
- US / EU data residency
- DPA available
- GDPR and CCPA aligned
- Change management
- Logging and alerting
- Disaster recovery tested
- Access revocation on offboarding
- Confidentiality agreements
- Continuous control monitoring
Evidence, on request.
Reports and agreements are shared with reviewers under a mutual NDA. Request what you need and a team member follows up to grant access.
Who touches your data.
Customers are notified 30 days before any subprocessor change. The current list is maintained in our Privacy Policy.
Answers for your review.
Vantage is built and hosted on MindStudio, which holds SOC 2 Type I and Type II certification. Vantage inherits MindStudio\u2019s certified infrastructure and security controls. Vantage\u2019s own organizational SOC 2 audit is in progress (Type I Q2 2026, Type II target Q3 2026), layered on top of the certified platform.
Customer data is hosted on AWS through the MindStudio platform, in US regions by default. EU customers can be provisioned in EU regions, with US and EU data segregation enforced at the infrastructure level.
No. Vantage does not train models on customer data. Founder updates, valuation letters, and personal investment data flow through inference-only pipelines with our model providers under zero-retention terms. No fine-tuning, no embedding training, no transfer to any provider\u2019s training corpus.
Every firm operates in its own tenant with a dedicated namespace. Access is enforced with role-based controls at the application and storage layers, and every read and write is recorded in an append-only audit log. Customer data never leaves its tenant.
Request it through the form below. A team member follows up to put a mutual NDA in place, then shares the MindStudio SOC 2 Type II report along with any other artifacts you need for your review.
Yes. A Data Processing Agreement is available on request and can be executed as part of onboarding. Request it below or raise it with your contact during a working session.
Request security documentation.
Tell us who you are and what you need. A team member follows up to put an NDA in place where required, then shares the reports and agreements for your review. Procurement and security reviews are welcome; no additional sales process required.