Security is a long-term commitment
Your goals are personal. We treat the data behind them with the same discipline the product is built on. Here is how we protect it.
Encryption everywhere
All traffic between your device and Mentorloop is encrypted in transit using TLS. Data stored on our infrastructure is encrypted at rest. Secrets and credentials are managed through a dedicated secrets manager and are never committed to source control.
Least-privilege access
Internal access to production systems is granted on a strict need-to-know basis and reviewed regularly. Administrative actions are logged, and access to customer data is limited to the minimum required to operate and support the service.
Resilient by design
We run automated, encrypted backups and rehearse recovery so your goal history is durable. Our infrastructure is designed for redundancy, and we monitor availability continuously.
Secure development
Changes go through code review and automated checks before release. We keep dependencies current, scan for known vulnerabilities, and follow secure-by-default practices across the stack.
Responsible disclosure
If you believe you have found a security vulnerability, we want to hear from you. Please email security@mentorloop.net with the details. We investigate every report and will keep you updated on our progress.
Questions
For any other security or compliance questions, reach out through our contact page. You can also review how we handle personal data in our Privacy Policy.