Trust center
Built for teams that can't be wrong about trust.
Mighty reads the documents your underwriting and claims systems depend on. This is how we handle that data: what we keep, what we never keep, and what your security team can review before you send us anything.
Compliance review
On request during procurement
SOC 2 / ISO 27001
Documentation on request
Responsible disclosure
security@trymighty.ai
Deployment diligence
Confirmed before go-live
Last updated: January 18, 2026
01The controls
What a security reviewer wants to see, in one place.
The controls below are the ones procurement and risk teams ask about most. We document each for your deployment so diligence moves faster, not slower.
Encryption
Files and data are encrypted in transit. Transport and storage protections are confirmed for your deployment during security review.
Data isolation
Every customer's traffic is kept separate. Tenant-aware key namespaces and isolation boundaries are reviewed as part of diligence.
No-retention default
Content is processed to return a verdict, not kept. Retention and audit metadata are configured per deployment, off by default.
Access control
API-key authentication for every scan, team roles in the dashboard, and key rotation and revocation. SSO and MFA are reviewed for enterprise.
Vulnerability management
Sensitive code paths are reviewed before release, dependencies are monitored, and fixes are prioritized by severity and customer impact.
Compliance review
Security, data-handling, and deployment posture are documented and walked through with your team during procurement, not asserted on a page.
02Data handling
Your content is handled, not harvested.
When a document comes through our API, it is processed to return a result, isolated from every other customer, and discarded by default. The line below is exact.
With your data, we
Do this
- Process content to return a single verdict, then discard it by default
- Isolate every customer's traffic from every other customer
- Keep audit metadata only when you turn it on, separated by your context
- Document where data is processed and confirm it before production traffic
- Support SSO, MFA, key rotation, and revocation for enterprise teams
And we never
Do this
- Train models on your content, ever, without explicit written consent
- Retain the documents, images, or text you send by default
- Store scan content in audit logs (logs capture metadata, not content)
- Share your data with other customers or sell it to third parties
- Move your deployment's data handling without telling you first
Deployment-specific controls are confirmed in writing during security review.
03Where it runs
Hardened where your documents land.
Hosted deployments run on cloud infrastructure with controls sized for API-based document scanning. The specifics are part of deployment diligence, not a marketing claim.
Segmented by design
Network segmentation, rate limiting, and abuse controls appropriate to the deployment.
Reviewed before go-live
Deployment, processing, and retention controls confirmed before any production traffic.
04Responsible disclosure
Found something? Tell us first.
We welcome responsible disclosure from the security community. Report a vulnerability to security@trymighty.ai and we'll acknowledge it promptly and work with you to resolve it.
What to include in a report
- Description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Any proof-of-concept code or screenshots
- Your contact information for follow-up
What we ask of researchers
- Give us reasonable time to investigate and fix before public disclosure
- Do not access, modify, or delete data belonging to other users
- Do not perform actions that could impact service availability
- Do not use automated scanning tools that generate excessive traffic
What we commit to in return
- Acknowledge good-faith reports promptly
- Provide regular updates on our progress
- Credit you in our security acknowledgments (if desired)
- No legal action against good-faith security researchers
05Security updates
Material changes, communicated.
We notify customers of material security updates that affect their use of the hosted service. Critical fixes are prioritized by severity, exploitability, and customer impact.
06Contact
Talk to security.
- Security & disclosure
- security@trymighty.ai
- General inquiries
- hi@trymighty.ai
- PGP key
- Available upon request
The anti-fraud signal
See what your intake is already missing.
Bring a sample of your real documents. We'll show you the edits and fakes your reviewers and automation can't see, before they reach a decision.