Trust signals
Every certification, compliance standard, and security measure we implement. Click any badge for proof.
SOC 2 Type II
In progressSOC 2 Type II audit in progress with target completion Q3 2026. Controls for security, availability, and confidentiality are implemented. Report will be available to enterprise customers upon completion.
Security details →GDPR compliant
CompliantFull GDPR compliance: data processing agreements, right to access/delete/port, consent management, DPO contact, and 72-hour breach notification. EU data processed in EU-West region.
Privacy policy →CCPA compliant
CompliantCalifornia Consumer Privacy Act compliance: right to know, right to delete, right to opt out, non-discrimination. We do not sell personal information.
Privacy policy →PIPEDA compliant
CompliantPersonal Information Protection and Electronic Documents Act compliance for Canadian users. Consent-based data collection, purpose limitation, and individual access rights.
Privacy policy →PCI-DSS secured
Via StripeAll payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. Mani never stores, processes, or transmits card data. Your payment information goes directly to Stripe.
Cookie policy (Stripe cookies) →99.9% uptime
LiveTarget uptime of 99.9% for all production services. Real-time status monitoring with public status page. Incident response within 15 minutes for critical issues.
Status page →No model training on your data
PolicyYour Brand DNA, generated content, and usage data are never used to train AI models. Your data is yours. Generation outputs are not shared between accounts or used to improve models for other customers.
Security page →AES-256-GCM + TLS 1.3
ActiveAll data encrypted at rest using AES-256-GCM. All data encrypted in transit using TLS 1.3. Database connections encrypted. Backups encrypted. No exceptions.
Security details →Infrastructure
| Hosting | Railway (managed PaaS) | Automatic scaling, zero-downtime deploys, built-in monitoring |
| Regions | US East + EU West | Data residency options for GDPR compliance |
| Database | PostgreSQL (encrypted) | Managed PostgreSQL with automated backups, point-in-time recovery |
| CDN | Cloudflare | DDoS protection, bot management, edge caching |
| Payments | Stripe | PCI-DSS Level 1, 3D Secure, fraud detection |
| Klaviyo + Resend | SPF, DKIM, DMARC configured. No open relays. |
Security
Technical details
Status
Real-time uptime
Privacy
Data handling
Cookies
Tracking policy
Security questions?
Enterprise customers can request our security questionnaire, vendor assessment, and SOC 2 report (when available).
Email security@maniai.com