Security
Effective date: July 18, 2026
Security is foundational to Predict.ai. This page summarizes the technical and organizational measures CelMind Corp. maintains to protect the platform and Customer Content. It supplements our Privacy Policy and Data Processing Addendum.
1. Infrastructure & Data Residency
- The platform runs on hardened cloud infrastructure with network isolation between environments and between customer workspaces.
- We operate multi-region deployments. Each workspace has a home region (selected explicitly or assigned from the customer's location), and Customer Content is stored and processed at rest in that region. EU-region workspaces keep Customer Content within the European Union; content is not moved to another region without the customer's instruction.
- Production access is restricted to authorized personnel, gated by multi-factor authentication, and logged.
2. Encryption
- All data in transit is encrypted with TLS 1.2 or higher.
- Customer Content and backups are encrypted at rest using industry-standard algorithms (AES-256 or equivalent).
- Secrets and credentials are stored in dedicated secret-management systems, never in source code.
3. Access Control & Tenancy
- Workspaces are logically isolated; role-based access control governs what each member and API token can do.
- The platform supports single sign-on, two-factor authentication, and scoped, revocable API tokens.
- Internal access to production data follows least-privilege principles and is reviewed periodically.
4. Secure Operations
- Changes ship through code review, automated testing, and staged deployments with rollback.
- We monitor the platform continuously, retain audit logs, and run automated alerting on anomalous activity.
- Dependencies and images are scanned for vulnerabilities; remediation is prioritized by severity.
- Data is backed up regularly and restoration procedures are tested.
5. Incident Response
We maintain an incident response process covering detection, triage, containment, remediation, and post-incident review. Customers are notified of personal data breaches affecting their Customer Content without undue delay, as described in the DPA.
6. Personnel
All personnel are bound by confidentiality obligations and receive security training. Access rights are revoked promptly upon role change or departure.
7. Vulnerability Reporting
We welcome reports from security researchers. If you believe you have found a vulnerability, email [email protected] with sufficient detail to reproduce it. Please do not access other customers' data, degrade the service, or publicly disclose the issue before we have had a reasonable opportunity to remediate. We will acknowledge reports promptly and will not pursue legal action against good-faith research conducted in line with these guidelines.
8. Contact
For security questionnaires, audit documentation, or any other security question, contact [email protected] or [email protected].