
Security & Compliance
MIND is built for systems that must be trusted — where security, auditability, and compliance are non-negotiable. Deterministic builds, cryptographic provenance, and documented audit controls; SOC 2 has not been audited.
Security posture
Deterministic builds
Covered deterministic integer, Q16.16, and strict scalar workloads can produce reproducible output given the same inputs. This enables verification of covered build artifacts and supply-chain records.
Cryptographic provenance
Build manifests can record SHA256 hashes of source code, dependencies, and compiler version where enabled. These records support provenance review for model artifacts.
Memory safety
Bounds checks and checked integer overflow are enabled by default for the supported language surface. Safety guarantees follow the documented compiler and runtime boundaries.
Pure-MIND cryptography
Crypto, TLS 1.3, and HTTP/2 primitives implemented in pure MIND and verified against RFC and NIST known-answer tests: AES-128-GCM, SHA-256, HKDF, X25519, SHA-3/SHAKE, RSA-PSS, ECDSA-P256, ML-KEM-768 (FIPS 203), X.509 parsing, HPACK, and HTTP/2 framing. A verified primitive library — a socket-driven TLS client is on the roadmap.
Audit logging
Commercial runtime includes structured audit logs for compilation events, deployments, and inference calls.
Vulnerability disclosure
Coordinated disclosure process for security issues. CVE assignment and patch releases following best practices.
Dependency scanning
Dependency scanning is part of the release workflow. SPDX 3.0 and CycloneDX 1.5 SBOM export, together with automated compliance reporting, are in development.
Compliance framework alignment
MIND's deterministic execution and audit logging provide artifacts for deployment-specific compliance review.
SOC 2 Type II
SOC 2 Type II is planned for MIND Cloud (hosted control plane); no audit has been completed and no report is available. Control mapping is in development; no audit or report is available.
HIPAA
On-premises and VPC deployment options can be assessed for customer programs using available audit trails, provenance, and redaction controls. No HIPAA certification, control mapping, or BAA artifact is published; any BAA requires separate technical and contractual review.
ISO/IEC 27001
ISO/IEC 27001 control mapping is planned for hosted offerings; no certification is claimed.
GDPR & Data Privacy
Data Processing Agreement (DPA) available for EU customers. Support for data residency requirements and right-to-deletion workflows.
Auditability features
Build reproducibility
Documented deterministic profiles can reproduce builds from the same source code, compiler version, and dependencies. This supports model artifact review in regulated environments.
- SHA256 hashing of build outputs
- Lockfile-based dependency pinning
- Compiler version manifests
Execution traces
Commercial runtime captures structured logs of model execution: inputs, outputs, timestamps, and resource usage. Supports audit review and incident investigation.
- Request-level tracing with correlation IDs
- Tamper-evident log storage
- Export to SIEM systems (Splunk, Datadog, etc.)
Model versioning & lineage
Track model lineage from training data to deployed artifacts. Provenance records support A/B testing and rollback; regulatory use requires deployment-specific review.
- Git-based source versioning
- Immutable artifact registry
- Training run metadata (dataset hashes, hyperparameters)
Compliance reporting
Compliance artifacts anchored on the tamper-evident compile-time evidence chain (RFC 0016). Automated SBOM, attestation, and report generation via mind_audit CLI tooling is in development.
- Tamper-evident compile-time evidence chain (shipped, RFC 0016)
- SPDX / CycloneDX SBOM export (in development)
- Audit-ready report generation for FDA, EU AI Act, ISO 26262 (in development)
Security vulnerability disclosure
We take security seriously. If you discover a security vulnerability in MIND, please report it responsibly.
How to report
Email security reports to info@star.ga. Please include:
- Description of the vulnerability
- Steps to reproduce
- Affected versions (if known)
- Your contact information for follow-up
We aim to acknowledge reports within 48 hours and provide a timeline for remediation. Coordinated disclosure: we ask that you do not publicly disclose until we have issued a patch.
Technical security documentation
For technical details on MIND's security architecture, see the full documentation.
View security docsQuestions about security or compliance?
Contact our team to discuss your specific security and compliance requirements.