Skip to main content

Security and privacy built in, not bolted on

HR software holds sensitive employee data. We treat it accordingly.

Last reviewed: 2026-09-05

Security by default

PIPEDA-Governed, GDPR-Aware

Data export & deletion tools

SSO / SAML

Growth+ tier

Encrypted Data

In transit and at rest

Role-Based Access

Admin, mentor, mentee isolation

Vulnerability Disclosure

Acknowledged within 24 hours

Your data is protected at every layer

MentorStack encrypts all data in transit using TLS. Data is encrypted at rest by our infrastructure providers, and sensitive fields like authentication tokens and integration keys get additional application-layer AES-256-GCM encryption. Participant data is private by default: only the matched pair and program admins can view session content.

Encryption in transit

All communication between your browser and MentorStack is encrypted using TLS 1.2 or higher, TLS 1.3 preferred.

Encryption at rest

Data is encrypted at rest by our infrastructure providers. Sensitive fields (authentication tokens and integration keys) receive additional application-layer AES-256-GCM encryption.

Canadian company, US infrastructure

MentorStack is Canadian. Infrastructure runs with US-based providers, named in full in our DPA. EEA and UK transfers to us rely on Canada's adequacy status; onward transfers to US providers are covered by Standard Contractual Clauses.

No AI model training

Your program data is never used to train AI models, not ours, not our vendors'.

PIPEDA-governed, GDPR-aware by design

MentorStack is PIPEDA-governed and GDPR-aware, with participant data-rights tools available from day one rather than bolted on later.

Right to export: admins and participants can export their data from their account
Right to deletion: account and program data can be deleted on request
Session data visibility: only matched participants and admins can see session content

Data Processing Agreement

A DPA is available for all accounts on request, covering standard contractual clauses and data processing obligations.

mentorstack.co/dpa

Privacy Policy

Full details on what data we collect, how it's used, and your rights as a data subject.

mentorstack.co/privacy

The right people see the right data

MentorStack enforces strict role-based access and organization-level data isolation.

SAML SSO

SAML 2.0 single sign-on available on Growth+ plans. Connect to any SAML-compliant identity provider.

Role-Based Access

Three distinct roles (admin, mentor, and mentee) each with scoped permissions. Admins can see program-wide data; participants only see their own.

Organization Isolation

Each organization's data is isolated with row-level security in the database and organization-scoped queries in the application.

Common security questions

Is MentorStack SOC 2 certified?
No. MentorStack does not hold SOC 2, ISO 27001, or a completed third-party penetration test. The practices on this page (encryption, role-based access, data isolation) describe what we do today. Contact us for our current security posture documentation.
Where is my data stored?
MentorStack is a Canadian company. Infrastructure runs with US-based providers, named in full in our DPA. Cross-border transfers rely on Canada's EU/UK adequacy status, with Standard Contractual Clauses covering onward transfers to US providers.
Do you train AI models on our data?
No. Your program data is never used to train AI models. All AI providers we use are named in our DPA and are contractually barred from training on data submitted through their APIs.
Can I export or delete our data?
Yes. Every participant exports or deletes their own data from their own account settings, without going through an administrator. Deletion runs on a 14-day cooling-off period the participant can cancel, and organization administrators are notified when it starts. For organization-wide export or deletion at the end of a subscription, contact privacy@mentorstack.co and see section 12 of the DPA.

Found a vulnerability?

For security questions or to report a vulnerability, please contact our security team directly. We acknowledge all security disclosures within 24 hours.

Ready to get started?

Your data is protected from day one. No credit card required.

Free for up to 10 participants. No credit card, no sales call. SSO on Growth and above. No SCIM needed at any tier.