Trust Center

Security and compliance, traceable to source.

Vantage is built and hosted on MindStudio, a SOC 2 Type I and Type II certified platform. Every control below is monitored continuously and evidenced on request.

Read the security overview
AttestationsCurrent
SOC 2 Type I
AICPA · VIA MINDSTUDIO
SOC 2 Type II
AICPA · VIA MINDSTUDIO
GDPR
EU · COMPLIANT
CCPA
CALIFORNIA · COMPLIANT

SOC 2 reports issued for MindStudio, the certified platform Vantage runs on. Last reviewed 06 / 2026.

Inherited Foundation

Built on certified infrastructure.

Vantage runs entirely on MindStudio, a platform that holds SOC 2 Type I and Type II certification. Hosting, encryption, network security, and infrastructure monitoring are inherited from that certified foundation, audited continuously by an independent firm.

On top of that foundation, Vantage adds its own application-layer controls: per-tenant isolation, method-level access control, and an append-only audit log of every read and write.

Vantage · Application Layer
Per-tenant isolationMethod-level RBACAppend-only audit logInference-only AI
Inherits ↓
AICPA SOCMindStudio · Certified Platform
SOC 2 Type ISOC 2 Type IIInfrastructure security24/7 monitoringEncryption at rest + in transitVendor risk management
Compliance

Where each framework stands.

An honest, two-layer view: certifications inherited from the MindStudio platform, alongside the frameworks Vantage is pursuing at the application layer.

SOC 2 Type I
Current
Issued for MindStudio, the platform Vantage runs on. Report available under NDA.
SOC 2 Type II
Current
Issued for MindStudio, the platform Vantage runs on. Report available under NDA.
SOC 2 (Vantage application)
In progress
Vantage’s own organizational audit. Type I Q2 2026, Type II target Q3 2026.
GDPR
Compliant
DPA available on request. EU data residency option for EU customers.
CCPA
Compliant
California opt-out and deletion flows in place. No sale of customer data.
ISO 27001
In progress
Information security management system operational. Certification audit Q4 2026.
Monitored Controls

What we monitor, continuously.

Thirty-six controls across six domains, monitored continuously through the certified platform. This is a representative summary; the full control matrix is available with the SOC 2 report.

36 CONTROLS · 6 DOMAINS · CONTINUOUSLY MONITORED · LAST SYNC 06 / 2026

Infrastructure6 controls
Continuously monitored
  • Encryption at rest (AES-256)
  • TLS 1.3 in transit
  • Network segmentation
  • DDoS protection
  • Continuous infrastructure monitoring
  • Automated backups, point-in-time recovery
Organizational6 controls
Continuously monitored
  • Security policies reviewed annually
  • Personnel background checks
  • Security awareness training
  • Incident response plan
  • Vendor risk management
  • Defined access roles
Product6 controls
Continuously monitored
  • Secure development lifecycle
  • Code review on every change
  • Dependency vulnerability scanning
  • Annual penetration testing
  • Per-action audit logging
  • Idempotency and retry safety
Access6 controls
Continuously monitored
  • Role-based access control
  • Per-tenant isolation
  • Passwordless authentication
  • Least-privilege enforcement
  • Quarterly access reviews
  • Customer-managed provisioning
Data & Privacy6 controls
Continuously monitored
  • Inference-only AI, no model training
  • No sale of customer data
  • Customer-controlled deletion in 30 days
  • US / EU data residency
  • DPA available
  • GDPR and CCPA aligned
Internal Procedures6 controls
Continuously monitored
  • Change management
  • Logging and alerting
  • Disaster recovery tested
  • Access revocation on offboarding
  • Confidentiality agreements
  • Continuous control monitoring
Documents & Resources

Evidence, on request.

Reports and agreements are shared with reviewers under a mutual NDA. Request what you need and a team member follows up to grant access.

SOC 2 Type II Report (MindStudio)
PDF · UNDER NDA
Penetration Test Summary
PDF · UNDER NDA
Data Processing Agreement (DPA)
PDF · AVAILABLE ON REQUEST
Architecture Overview
PDF · AVAILABLE ON REQUEST
Subprocessors

Who touches your data.

MindStudio
Platform hosting, compute, and certified infrastructure
United States
Amazon Web Services
Cloud infrastructure (via MindStudio)
US / EU
Anthropic
AI inferencezero retention
United States
OpenAI
AI inferencezero retention
United States
Google
AI inferencezero retention
United States
Transactional email
Notification and verification delivery
United States

Customers are notified 30 days before any subprocessor change. The current list is maintained in our Privacy Policy.

Common Questions

Answers for your review.

Vantage is built and hosted on MindStudio, which holds SOC 2 Type I and Type II certification. Vantage inherits MindStudio\u2019s certified infrastructure and security controls. Vantage\u2019s own organizational SOC 2 audit is in progress (Type I Q2 2026, Type II target Q3 2026), layered on top of the certified platform.

Customer data is hosted on AWS through the MindStudio platform, in US regions by default. EU customers can be provisioned in EU regions, with US and EU data segregation enforced at the infrastructure level.

No. Vantage does not train models on customer data. Founder updates, valuation letters, and personal investment data flow through inference-only pipelines with our model providers under zero-retention terms. No fine-tuning, no embedding training, no transfer to any provider\u2019s training corpus.

Every firm operates in its own tenant with a dedicated namespace. Access is enforced with role-based controls at the application and storage layers, and every read and write is recorded in an append-only audit log. Customer data never leaves its tenant.

Request it through the form below. A team member follows up to put a mutual NDA in place, then shares the MindStudio SOC 2 Type II report along with any other artifacts you need for your review.

Yes. A Data Processing Agreement is available on request and can be executed as part of onboarding. Request it below or raise it with your contact during a working session.

Request Access

Request security documentation.

Tell us who you are and what you need. A team member follows up to put an NDA in place where required, then shares the reports and agreements for your review. Procurement and security reviews are welcome; no additional sales process required.

Reports are shared under a mutual NDA. By submitting, you consent to being contacted about your request.