Security at MANDA Institute
What we actually do to protect your data, stated plainly and without overclaiming.
- We tell you what is true, not what sounds impressive.
- Many security pages make claims that are misleading or unverified. This page describes only the security measures we have actually implemented. We do not claim certifications we have not earned, and we do not overstate what our infrastructure does.
- Implemented security controls
- Strong password hashing
- User passwords are never stored in plain text. We use scrypt (Node.js native crypto) with per-user random salts to store password verifiers. Even in the event of a database breach, passwords cannot be reversed.
- Encrypted connections (HTTPS / TLS)
- All traffic between your browser and our servers is encrypted using TLS. In production, TLS is enforced at the infrastructure level. Unencrypted HTTP connections are not accepted.
- Per-user ownership enforcement
- Every API endpoint that accesses company data, valuations, documents or financials verifies the requesting user's ownership on the server side. There is no client-supplied trust: ownership is derived from the authenticated session against the database record.
- Managed Postgres, encrypted at rest
- All data is stored in Neon Serverless PostgreSQL and encrypted at rest by the database infrastructure, with access restricted to the application. Our database region is currently in the United States, so personal data is transferred outside the EEA; our Privacy Policy sets out how those transfers are handled.
- Full audit logging
- Every AI agent action, every valuation run, every document access and every human review decision is recorded in an append-only audit log. These records are used to investigate anomalies and demonstrate accountability.
- Human review before every valuation is final
- MANDA operates as an AI-first platform. The AI agents perform the computational work, but no client-facing valuation is presented as final until a human has reviewed and approved it. AI output is never unchecked.
- Authentication and session security
- Sessions are managed server-side using signed, HttpOnly cookies. CSRF tokens are required on all state-modifying requests. Auth endpoints are rate-limited in production to limit brute-force attempts.
- Sentry error monitoring
- Runtime errors and exceptions are captured by Sentry, with alerts routed to the engineering team. Error reports do not include user passwords, session tokens or raw financial data.
- Honest about our current status.
- The following are things we have not yet achieved and will not claim until we have:
- Found a vulnerability?
- If you discover a security vulnerability in MANDA Institute, please report it responsibly. We will acknowledge your report within 3 business days and work with you to resolve the issue before any public disclosure.
- Please include a clear description of the issue, the steps to reproduce it, and the potential impact. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.
- GDPR rights you can exercise right now
- These rights are implemented, not just documented. You can exercise the first three directly from your account settings without contacting us.
- You can download a complete copy of all your personal data at any time from your profile settings.
- You can request permanent deletion of your account and all associated data directly from your profile settings. This includes companies, valuations, financials, documents, and chat history. Deletion is permanent and irreversible.
- Right to data portability (Art. 20)
- Your data export is provided as machine-readable JSON, covering all your profile data, companies, financials, valuations and documents.
- You may object to processing at any time by contacting us at tech@manda.institute.
- When you delete your account, all personal data is permanently removed. AI agent audit log entries that reference your account ID are retained in anonymised form (the user ID is nulled) to maintain the integrity of the operational audit trail, as permitted under GDPR Art. 17(3)(b) for legal obligation compliance. These entries contain no name, email or other personal identifiers after anonymisation.
- Get in touch with our team.
- For security questions, vulnerability reports, or data protection enquiries, contact us at tech@manda.institute.
- Built for European businesses
- Free to start. No account needed for the instant benchmark.
- The one success fee we intend to charge, only when a deal closes.
- The instant benchmark takes under 60 seconds.
- Owners across the EU, EEA, UK and wider Europe can use the valuation form.
- Export or permanently delete everything we hold, any time.
- Manufacturing & industry
- Technology & telecoms
- Consumer, retail & media
- Healthcare & education
- Professional & financial services
- Energy, transport & agriculture
- FOR BUYERS
- FOR SELLERS
- Ready to know your number?
- The instant benchmark gives you an indicative value range in under 60 seconds, measured against completed sales of medium sized European businesses. The full valuation takes about 5 minutes, uses your own financials and shows up to four methods. Both are free. Both are indicative estimates, not a formal appraisal.
- The one success fee we intend to charge applies only when a deal closes. Provisional. No engagement letter has been drafted yet, so this is how we intend to charge rather than terms you can hold us to.
See what it's worth