Security & Trust
Your Data, Protected
Mavlon processes sensitive manufacturing information - technical drawings, specifications, inspection characteristics, and first article inspection records. We protect that information through customer-selected deployment options, encryption, access controls, contractual protections for AI processing, and a human-auditable workflow. Our Information Security Management System is being built on the ISO/IEC 27001:2022 framework.
Compliance Roadmap
Mavlon is actively pursuing ISO/IEC 27001:2022 certification. Our Information Security Management System (ISMS) is built on the ISO 27001 framework, and we are progressing through a structured certification timeline. The dates below are targets, not current certifications. We also track SOC 2 and EU NIS2 requirements where they are relevant to our operations and customers' supply-chain due diligence.
Encryption & Data Protection
Mavlon-managed deployments encrypt customer data in transit and at rest using industry-standard cryptographic protocols. Data is decrypted only when needed for authorized processing. Security controls for customer-controlled cloud and on-premises deployments are shared with, or operated by, the customer as documented in the applicable agreement.
| Layer | Standard | Detail |
|---|---|---|
| Data in Transit | TLS 1.2 / 1.3 | All API and web communications enforced via HTTPS |
| Data at Rest | AES-256 | Cloud-native encryption with managed key rotation |
| Backups | AES-256 | Encrypted and stored in geographically separate locations |
| Secrets | Vault-managed | All credentials and API keys stored in secure vaults, never hardcoded |
Access Control & Authentication
Access to all Mavlon systems and customer data is governed by the Principle of Least Privilege. Every access decision is deliberate and auditable.
- Multi-Factor Authentication (MFA) is required for all production systems, cloud consoles, and administrative access.
- Role-Based Access Control (RBAC) governs access to customer data and internal systems. Permissions are granted on a need-to-know basis.
- Unique identities for every user. Shared accounts are prohibited.
- Access logging - all access to production environments is logged and auditable.
- Tenant isolation - customer data is logically segregated. No customer can access another customer's data.
- Immediate revocation upon termination of any employment or contractor relationship.
Infrastructure Security
Mavlon's platform runs on enterprise-grade cloud infrastructure provided by vendors that maintain SOC 2 Type II and ISO 27001 certifications.
- Network segmentation and firewalls isolate production workloads.
- Regular patching and automated vulnerability scanning across all systems.
- Continuous monitoring and alerting for anomalous activity.
- Automated daily backups with tested point-in-time recovery.
- Staging and production environments are strictly separated.
Incident Response
Mavlon maintains a documented Incident Response Plan with defined procedures for identification, containment, eradication, recovery, and post-incident review.
| Commitment | Timeline |
|---|---|
| Initial customer notification | Within 24 hours of confirmed incident |
| Detailed incident report | Within 72 hours |
| Root cause analysis & remediation | Within 30 days |
| Regulatory notification (GDPR / NIS2) | Within 72 hours as required by law |
Business Continuity & Disaster Recovery
Our business continuity measures are designed to minimize disruption and ensure your operations are never left waiting.
- RTO (Recovery Time Objective): 4 hours for critical systems.
- RPO (Recovery Point Objective): 24 hours maximum acceptable data loss.
- Automated daily backups with periodic restoration testing.
- Documented disaster recovery procedures covering all critical services.
Data Handling & Privacy
Mavlon applies data-protection controls based on the selected deployment and applicable customer agreement. Our Privacy Policy and customer DPAs describe how data is stored, processed, transferred, and retained.
| Aspect | Practice |
|---|---|
| Data Residency | Customer-selected Mavlon-managed cloud region, customer-controlled cloud, or on-premises deployment, as documented in the order form |
| Retention | Trial drawings deleted from active systems within 7 days after trial analysis. Paid-service data follows the customer agreement and is deleted from active Mavlon-managed systems within 30 days after termination when no different period is agreed. |
| Model Training | Customer drawings, specifications, prompts, corrections, and outputs are not used to train Mavlon or third-party general-purpose models |
| Portability | Full data export in standard formats available at any time upon request |
| Sub-processors | Maintained register available upon request. Commercial AI providers that process customer content are covered by DPAs or equivalent contractual data-protection terms. |
| Customer DPA | Data Processing Agreement available to customers that require one |
| Classification | All customer data classified as Confidential by default |
AI Processing & Model Choice
Customer content is processed only to provide the requested drawing analysis and FAI workflow. It is not used to train, fine-tune, or improve Mavlon models or any third-party general-purpose model.
- Commercial AI inference is provided through business or API services covered by contractual data-protection terms, including DPAs or equivalent protections, with provider training disabled.
- Supported open-source model configurations are available for customers that require customer-controlled cloud or on-premises processing.
- The selected model providers, processing locations, and operational responsibilities are documented for the customer's deployment.
- AI outputs remain drafts until reviewed and approved by authorized engineering or quality personnel.
Secure Development
Security is integrated throughout our software development lifecycle.
- Mandatory code reviews for all changes to production systems.
- Automated dependency scanning for known vulnerabilities.
- Credentials managed through secure vaults. Hardcoding is prohibited.
- Separate staging and production environments with controlled promotion.
Supply Chain & Third-Party Security
Third-party service providers with access to Mavlon systems or customer content are subject to risk-based review before engagement. Contracts include confidentiality, security, and data-protection requirements appropriate to the service. Commercial AI providers used for customer-content processing are covered by DPAs or equivalent protections and configured not to use that content for model training. A register of sub-processors is maintained and available to customers upon request.
For customers subject to NIS2: Mavlon's security practices are designed to support your supply chain due diligence obligations under the EU NIS2 Directive. We provide the documentation and transparency needed for your vendor risk assessments.
Documentation Available on Request
The following security documentation is available to prospective and current customers. Contact us to request access.
- Information Security Policy
- Incident Response Plan
- Data Processing Agreement
- Sub-processor Register
- Security Practices Overview
A penetration test summary will be added after the planned Q4 2026 third-party testing and remediation are complete.
Security Contact
Questions or concerns?
For security-related inquiries, vulnerability reports, or to request any of the documentation listed above, reach out to us directly.
atishay@mavlon.co
Response time: Within 1 business day.
This page is reviewed and updated periodically. Last updated: July 13, 2026.