MindNote Trust Center

Trust, security &
compliance you can verify.

MindNote is following security checklists for startups and enterprise teams in regulated industries. Your data will train a personal predictive model for your own future note-taking. The future roadmap includes BAA, SOC 2 Type II, and HIPAA compliance.

SCANNING
Compliance roadmap

Where we are,
and where we're going

A transparent view of our compliance program — the certifications already in place and the ones we're working toward.

4 of 7 milestones live57%
  • GDPR Compliant

    Live

    EU data subject rights — consent, portability and deletion flows live in-app.

    GDPR Compliant

    Live

    EU data subject rights — consent, portability and deletion flows live in-app.

  • CCPA / CPRA Compliant

    Live

    California rights to know, delete and opt-out — fully implemented.

    CCPA / CPRA Compliant

    Live

    California rights to know, delete and opt-out — fully implemented.

  • Workspace Isolation

    Live

    Per-tenant access controls isolate every workspace at the data layer.

    Workspace Isolation

    Live

    Per-tenant access controls isolate every workspace at the data layer.

  • PCI DSS — Offloaded

    Live

    Payments are processed by Gumroad, Apple App Store and Google Play Billing. MindNote never sees or stores card or payment details.

    PCI DSS — Offloaded

    Live

    Payments are processed by Gumroad, Apple App Store and Google Play Billing. MindNote never sees or stores card or payment details.

  • SOC 2 Type II

    Planned

    Targeted as part of our enterprise readiness program.

    SOC 2 Type II

    Planned

    Targeted as part of our enterprise readiness program.

  • HIPAA + BAA

    Planned

    Healthcare-grade controls and BAA on the roadmap for regulated customers.

    HIPAA + BAA

    Planned

    Healthcare-grade controls and BAA on the roadmap for regulated customers.

  • ISO 27001

    Planned

    Targeted alongside SOC 2 within our broader certification roadmap.

    ISO 27001

    Planned

    Targeted alongside SOC 2 within our broader certification roadmap.

Security features

Built for teams that need answers, not promises

Every MindNote workspace ships with the controls your security and legal teams expect.

Your data stays yours

Our AI partners are contractually barred from training on your content. MindNote may use your own notes to power personal suggestions just for you — revocable at any time.

Private by design

Your content is kept separate from every other account. Only you and the people you invite can ever see it.

Authenticated access

Verified email or Google sign-in required. No guest or anonymous access. Session management with automatic renewal.

We never touch your cards

Payments are handled by trusted, PCI-certified providers. MindNote stores zero payment data.

Encrypted end-to-end

Your notes are protected with industry-standard encryption — both in transit and at rest — on a SOC 2-compliant platform.

Compliant partners

We only work with subprocessors who maintain BAA, SOC 2 Type II, HIPAA and GDPR compliance. Full list public.

Documents

Everything procurement
will ask for

Browse our agreements, security docs and operational guides. Request restricted items in one click.

Help center

Compliance-focused help articles

Practical guides written for security, legal and IT teams rolling out MindNote.

Request access

Need our LOI, DPA, MSA, or security Q&A?

Tell us a little about your company and we'll send your access code for restricted documents — usually within one business day.

By submitting you agree to our Privacy Policy. We respond within 1 business day.