Security & trust

Built to procurement standards.

Myndlab is operated by Permus, a Dubai engineering firm certified ISO 9001 and ISO/IEC 27001:2022. Everything your security, legal, and procurement teams need — right here.

Certified 13 May 2026 · Gabriel Registrar · Valid till May 2029
Myndlab · Certifications
Active
ISO/IEC 27001:2022
Information security
Valid till May 2029
ISO 9001:2015
Quality management
Valid till May 2029
GDPR
EU data protection
Ongoing
ISO/IEC 42001:2023
AI management
In progress
Certified 13 May 2026 · Gabriel Registrar · EIAC accredited
Certifications

Certified. Audited. Renewed.

Information security

ISO/IEC 27001:2022

Certified by Gabriel Registrar (EIAC accredited). Covers information security, cybersecurity and privacy protection. Certificate no. 07020001076.

Since May 2026 · Renews May 2029
Quality management

ISO 9001:2015

Certified by Gabriel Registrar (EIAC accredited). Covers software design, development, and AI solutions delivery. Certificate no. 07020001075.

Since May 2026 · Renews May 2029
EU data protection

GDPR compliant

DPA available. Designated Data Protection Officer. Data subject rights honored.

Since 2024 · Renews Ongoing
AI management

ISO/IEC 42001:2023

AI management system certification in progress. Covers responsible AI governance, risk and impact assessment.

Since In progress · Renews 2026
Security practices

How we protect your data.

K

Encryption in transit and at rest

TLS 1.3 for every connection. AES-256 on disk. Bring-your-own-key (BYOK) available on Enterprise.

U

RBAC + SSO + audit logs

SAML 2.0, OIDC, SCIM provisioning, custom roles, exportable audit logs streamed to your SIEM.

P

Annual penetration testing

Third-party pen-test report annually. Shareable under NDA. Findings tracked to closure.

S

Automated vulnerability scanning

SAST + DAST on every commit. Snyk, Dependabot, security gates in CI before any deploy.

Backups + point-in-time restore

Daily snapshots retained 30 days. RPO 1 hour. RTO 4 hours. Restore drills run quarterly.

!

24/7 incident response

Round-the-clock response team. Customer notification within 72 hours of any confirmed breach.

Data residency

Your data stays in your region.

Three sovereign regions live today. Three more on the 2026/27 roadmap. Pick your region at signup — data never leaves it.

UAE-N
Live
United Arab Emirates (North)
Dubai
Launched Apr 2026
SAU-C
Live
Saudi Arabia (Central)
Riyadh
Launched May 2026
EU-C
Live
European Union (Central)
Frankfurt
Launched Mar 2026
QAT
Planned
Qatar
Doha
Target Q4 2026
BAH
Planned
Bahrain
Manama
Target Q1 2027
OMA
Planned
Oman
Muscat
Target Q2 2027
Compliance commitments

Vetted partners.
Governed data flows.

Myndlab works with a curated set of infrastructure, AI, and payment providers — every one governed by a signed Data Processing Agreement and bound to the same regional residency guarantees as your workspace.

Need the full list of subprocessors for your DPA review? We'll send it over within one business day.

Request subprocessor list →
DPA with every provider
No vendor processes customer data without a signed, GDPR-aligned Data Processing Agreement.
Regional residency enforced
Providers are contractually bound to process data only within your chosen region.
Annual vendor reviews
Every subprocessor is re-evaluated annually for security posture, compliance status, and breach history.
Change notifications
We notify customers at least 30 days before adding or replacing any subprocessor.
Legal & security documents

Need a document? Just ask.

Our legal and security documentation is available on request. Email us with what you need and we'll respond within one business day.

Get in touch

Questions about security?

Whether you're a procurement team running a security review, a customer with a compliance question, or a researcher who found something — we're here and we respond fast.