Trust center

Built for teams that can't be wrong about trust.

Mighty reads the documents your underwriting and claims systems depend on. This is how we handle that data: what we keep, what we never keep, and what your security team can review before you send us anything.

Compliance review

On request during procurement

SOC 2 / ISO 27001

Documentation on request

Responsible disclosure

security@trymighty.ai

Deployment diligence

Confirmed before go-live

Last updated: January 18, 2026

01The controls

What a security reviewer wants to see, in one place.

The controls below are the ones procurement and risk teams ask about most. We document each for your deployment so diligence moves faster, not slower.

Encryption

Files and data are encrypted in transit. Transport and storage protections are confirmed for your deployment during security review.

Data isolation

Every customer's traffic is kept separate. Tenant-aware key namespaces and isolation boundaries are reviewed as part of diligence.

No-retention default

Content is processed to return a verdict, not kept. Retention and audit metadata are configured per deployment, off by default.

Access control

API-key authentication for every scan, team roles in the dashboard, and key rotation and revocation. SSO and MFA are reviewed for enterprise.

Vulnerability management

Sensitive code paths are reviewed before release, dependencies are monitored, and fixes are prioritized by severity and customer impact.

Compliance review

Security, data-handling, and deployment posture are documented and walked through with your team during procurement, not asserted on a page.

Control families

02Data handling

Your content is handled, not harvested.

When a document comes through our API, it is processed to return a result, isolated from every other customer, and discarded by default. The line below is exact.

With your data, we

Do this

  • Process content to return a single verdict, then discard it by default
  • Isolate every customer's traffic from every other customer
  • Keep audit metadata only when you turn it on, separated by your context
  • Document where data is processed and confirm it before production traffic
  • Support SSO, MFA, key rotation, and revocation for enterprise teams

And we never

Do this

  • Train models on your content, ever, without explicit written consent
  • Retain the documents, images, or text you send by default
  • Store scan content in audit logs (logs capture metadata, not content)
  • Share your data with other customers or sell it to third parties
  • Move your deployment's data handling without telling you first

Deployment-specific controls are confirmed in writing during security review.

03Where it runs

Hardened where your documents land.

Hosted deployments run on cloud infrastructure with controls sized for API-based document scanning. The specifics are part of deployment diligence, not a marketing claim.

Segmented by design

Network segmentation, rate limiting, and abuse controls appropriate to the deployment.

Reviewed before go-live

Deployment, processing, and retention controls confirmed before any production traffic.

04Responsible disclosure

Found something? Tell us first.

We welcome responsible disclosure from the security community. Report a vulnerability to security@trymighty.ai and we'll acknowledge it promptly and work with you to resolve it.

What to include in a report

  • Description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any proof-of-concept code or screenshots
  • Your contact information for follow-up

What we ask of researchers

  • Give us reasonable time to investigate and fix before public disclosure
  • Do not access, modify, or delete data belonging to other users
  • Do not perform actions that could impact service availability
  • Do not use automated scanning tools that generate excessive traffic

What we commit to in return

  • Acknowledge good-faith reports promptly
  • Provide regular updates on our progress
  • Credit you in our security acknowledgments (if desired)
  • No legal action against good-faith security researchers

05Security updates

Material changes, communicated.

We notify customers of material security updates that affect their use of the hosted service. Critical fixes are prioritized by severity, exploitability, and customer impact.

06Contact

Talk to security.

Security & disclosure
security@trymighty.ai
General inquiries
hi@trymighty.ai
PGP key
Available upon request

The anti-fraud signal

See what your intake is already missing.

Bring a sample of your real documents. We'll show you the edits and fakes your reviewers and automation can't see, before they reach a decision.