Security and privacy built in, not bolted on
HR software holds sensitive employee data. We treat it accordingly.
Security by default
GDPR-Aligned
Data export & deletion tools
SSO / SAML
Growth+ tier
Encrypted Data
In transit and at rest
Role-Based Access
Admin, mentor, mentee isolation
SOC 2
Policies in place; audit planned
Your data is protected at every layer
MentorStack encrypts all data in transit using TLS. Data is encrypted at rest by our infrastructure providers, and sensitive fields like authentication tokens and integration keys get additional application-layer AES-256-GCM encryption. Participant data is private by default: only the matched pair and program admins can view session content.
Encryption in transit
All communication between your browser and MentorStack is encrypted using TLS 1.3.
Encryption at rest
Data is encrypted at rest by our infrastructure providers. Sensitive fields (authentication tokens and integration keys) receive additional application-layer AES-256-GCM encryption.
Data residency: North America
Primary database storage is in North America. Some content may be cached at global edge locations via our CDN to ensure performance. International data transfers are covered by Standard Contractual Clauses.
No AI model training
Your program data is never used to train AI models, not ours, not our vendors'.
GDPR-aligned by design
MentorStack is built around GDPR principles, with participant data-rights tools available from day one rather than bolted on later.
Data Processing Agreement
A DPA is available for all accounts on request, covering standard contractual clauses and data processing obligations.
mentorstack.co/dpaPrivacy Policy
Full details on what data we collect, how it's used, and your rights as a data subject.
mentorstack.co/privacyThe right people see the right data
MentorStack enforces strict role-based access and organization-level data isolation.
SAML SSO
SAML 2.0 single sign-on available on Growth+ plans. Connect to any SAML-compliant identity provider.
Role-Based Access
Three distinct roles (admin, mentor, and mentee) each with scoped permissions. Admins can see program-wide data; participants only see their own.
Organization Isolation
Each organization's data is fully isolated. No cross-tenant data access is possible at any layer of the stack.
Common security questions
- Is MentorStack SOC 2 certified?
- Not yet. Our SOC 2 control policies are in place and an independent audit is planned. Contact us for our current security posture documentation.
- Where is my data stored?
- Primary database storage is in North America. Some content may be cached at global edge locations via our CDN provider (Cloudflare) to ensure performance. International data transfers are covered by Standard Contractual Clauses.
- Do you train AI models on our data?
- No. Your program data is never used to train AI models.
- Can I export or delete our data?
- Yes. Data export and deletion tools are available to all accounts from your admin settings.
Found a vulnerability?
For security questions or to report a vulnerability, please contact our security team directly. We respond to all security disclosures within one business day.
Ready to get started?
Your data is protected from day one. No credit card required.