Platform
Overview Mind Products Deployment
Industries
Banking Insurance Securities Retail
Company
About Us Careers Press
More
Case Studies Get in touch
Trust · Security & Compliance

Trust Center

How Colendi AI keeps regulated work secure: certifications, data and model governance, deployment options from SaaS to air-gapped, and the providers we rely on. Reports and detailed documentation are available on request.

Certifications

Audited, certified, compliant.

Independently audited, and compliant with the regulations our customers answer to. Reports are available under NDA on request.

AICPA SOC 2SOC 2Independently audited controls for security, availability and confidentiality.
ISO 27001ISO 27001Certified information security management system across the platform.
KVKKKVKKCompliant with Türkiye's Personal Data Protection Law No. 6698.
EU GDPR CompliantGDPRCompliant processing for customers subject to EU and UK data protection law.
Data & model governance

Governed by design,
not by promise.

Data stays where regulation says it must stay — and no model output becomes an action without passing governance.

Data residency

Kept in region

Customer data is stored in Türkiye by default, with residency options that respect local regulation in every deployment.

Protection

Encrypted & redacted

Encryption in transit and at rest, PII redaction before inference, and zero retention with model providers.

Access

Controlled & logged

Role-based access controls, with every access to personal data and every action on a case logged and auditable.

Model oversight

Evaluated continuously

Complete-case grading, regression tests on every release, and a published pass rate for every production module.

Human authority

Approval gates

High-stakes actions require human decision — with a named owner, an escalation path and a clock.

Auditability

Reconstructable decisions

Inputs, checks, decider and outcome are recorded immutably; every decision can be reconstructed after the fact.

Deployment

The isolation level your regulator requires.

The same governed platform, from managed SaaS to fully air-gapped — chosen with your risk team, not imposed on it.

OptionInfrastructureData boundaryUpdates
Multi-tenantManaged cloud with secure logical isolationIn-region residency, tenant-level separationContinuous, fully monitored
Single tenantDedicated, fully isolated infrastructureDedicated data plane, custom configurationAutomatic, on your schedule
Your cloudRuns inside your own cloud accountData never leaves your organizationYou control governance and timing
On-premiseFully air-gapped, zero external dependenciesEverything stays on siteMaintained on site with your team
Sub-processors

The providers we rely on.

Scope varies by deployment option — on-premise deployments have zero external dependencies. Full, current list available on request.

ProviderPurposeNotes
AWSCloud infrastructureRegion selected per deployment
Google CloudCloud infrastructureRegion selected per deployment
Microsoft AzureCloud infrastructureRegion selected per deployment
Meta PlatformsWhatsApp Business messaging channelWhere messaging channels are in scope
Model providersCommercial and open-source LLM inferenceZero retention; PII redacted before inference
Responsible AI

Six commitments, one standard.

Oversight, guardrails, explainability, data protection, fairness and continuous evaluation shape how every Mind product is designed, deployed and governed. Read them in full on our AI Safety page.

Security reviews, due-diligence questionnaires and reports: info@colendiai.com

Bring your security review. We're ready.

Get in touch