Compliance Roadmap

Mavlon is actively pursuing ISO/IEC 27001:2022 certification. Our Information Security Management System (ISMS) is built on the ISO 27001 framework, and we are progressing through a structured certification timeline. The dates below are targets, not current certifications. We also track SOC 2 and EU NIS2 requirements where they are relevant to our operations and customers' supply-chain due diligence.

Completed
ISMS Foundation & Policy Framework
Information Security Policy, risk assessment methodology, asset inventory, access control policies, incident response procedures, and business continuity planning.
Q3 2026 - Current
Control Implementation & Risk Treatment
Implementing ISO 27001 Annex A controls, completing risk treatment plans, supplier security assessments, and documentation of all operational procedures.
Q4 2026
Internal Audit & Penetration Testing
Internal ISMS audit, third-party penetration testing, gap remediation, and management review.
Q1 2027 - Target
ISO 27001 Certification Audit
Stage 1 (documentation review) and Stage 2 (certification evaluation) with an accredited certification body.

Encryption & Data Protection

Mavlon-managed deployments encrypt customer data in transit and at rest using industry-standard cryptographic protocols. Data is decrypted only when needed for authorized processing. Security controls for customer-controlled cloud and on-premises deployments are shared with, or operated by, the customer as documented in the applicable agreement.

Layer Standard Detail
Data in Transit TLS 1.2 / 1.3 All API and web communications enforced via HTTPS
Data at Rest AES-256 Cloud-native encryption with managed key rotation
Backups AES-256 Encrypted and stored in geographically separate locations
Secrets Vault-managed All credentials and API keys stored in secure vaults, never hardcoded

Access Control & Authentication

Access to all Mavlon systems and customer data is governed by the Principle of Least Privilege. Every access decision is deliberate and auditable.

  • Multi-Factor Authentication (MFA) is required for all production systems, cloud consoles, and administrative access.
  • Role-Based Access Control (RBAC) governs access to customer data and internal systems. Permissions are granted on a need-to-know basis.
  • Unique identities for every user. Shared accounts are prohibited.
  • Access logging - all access to production environments is logged and auditable.
  • Tenant isolation - customer data is logically segregated. No customer can access another customer's data.
  • Immediate revocation upon termination of any employment or contractor relationship.

Infrastructure Security

Mavlon's platform runs on enterprise-grade cloud infrastructure provided by vendors that maintain SOC 2 Type II and ISO 27001 certifications.

  • Network segmentation and firewalls isolate production workloads.
  • Regular patching and automated vulnerability scanning across all systems.
  • Continuous monitoring and alerting for anomalous activity.
  • Automated daily backups with tested point-in-time recovery.
  • Staging and production environments are strictly separated.

Incident Response

Mavlon maintains a documented Incident Response Plan with defined procedures for identification, containment, eradication, recovery, and post-incident review.

Commitment Timeline
Initial customer notification Within 24 hours of confirmed incident
Detailed incident report Within 72 hours
Root cause analysis & remediation Within 30 days
Regulatory notification (GDPR / NIS2) Within 72 hours as required by law

Business Continuity & Disaster Recovery

Our business continuity measures are designed to minimize disruption and ensure your operations are never left waiting.

  • RTO (Recovery Time Objective): 4 hours for critical systems.
  • RPO (Recovery Point Objective): 24 hours maximum acceptable data loss.
  • Automated daily backups with periodic restoration testing.
  • Documented disaster recovery procedures covering all critical services.

Data Handling & Privacy

Mavlon applies data-protection controls based on the selected deployment and applicable customer agreement. Our Privacy Policy and customer DPAs describe how data is stored, processed, transferred, and retained.

Aspect Practice
Data Residency Customer-selected Mavlon-managed cloud region, customer-controlled cloud, or on-premises deployment, as documented in the order form
Retention Trial drawings deleted from active systems within 7 days after trial analysis. Paid-service data follows the customer agreement and is deleted from active Mavlon-managed systems within 30 days after termination when no different period is agreed.
Model Training Customer drawings, specifications, prompts, corrections, and outputs are not used to train Mavlon or third-party general-purpose models
Portability Full data export in standard formats available at any time upon request
Sub-processors Maintained register available upon request. Commercial AI providers that process customer content are covered by DPAs or equivalent contractual data-protection terms.
Customer DPA Data Processing Agreement available to customers that require one
Classification All customer data classified as Confidential by default

AI Processing & Model Choice

Customer content is processed only to provide the requested drawing analysis and FAI workflow. It is not used to train, fine-tune, or improve Mavlon models or any third-party general-purpose model.

  • Commercial AI inference is provided through business or API services covered by contractual data-protection terms, including DPAs or equivalent protections, with provider training disabled.
  • Supported open-source model configurations are available for customers that require customer-controlled cloud or on-premises processing.
  • The selected model providers, processing locations, and operational responsibilities are documented for the customer's deployment.
  • AI outputs remain drafts until reviewed and approved by authorized engineering or quality personnel.

Secure Development

Security is integrated throughout our software development lifecycle.

  • Mandatory code reviews for all changes to production systems.
  • Automated dependency scanning for known vulnerabilities.
  • Credentials managed through secure vaults. Hardcoding is prohibited.
  • Separate staging and production environments with controlled promotion.

Supply Chain & Third-Party Security

Third-party service providers with access to Mavlon systems or customer content are subject to risk-based review before engagement. Contracts include confidentiality, security, and data-protection requirements appropriate to the service. Commercial AI providers used for customer-content processing are covered by DPAs or equivalent protections and configured not to use that content for model training. A register of sub-processors is maintained and available to customers upon request.

For customers subject to NIS2: Mavlon's security practices are designed to support your supply chain due diligence obligations under the EU NIS2 Directive. We provide the documentation and transparency needed for your vendor risk assessments.

Documentation Available on Request

The following security documentation is available to prospective and current customers. Contact us to request access.

  • Information Security Policy
  • Incident Response Plan
  • Data Processing Agreement
  • Sub-processor Register
  • Security Practices Overview

A penetration test summary will be added after the planned Q4 2026 third-party testing and remediation are complete.

Security Contact

Questions or concerns?

For security-related inquiries, vulnerability reports, or to request any of the documentation listed above, reach out to us directly.

atishay@mavlon.co

Response time: Within 1 business day.

This page is reviewed and updated periodically. Last updated: July 13, 2026.