Security / trust posture

Security for senior-leader ideas

Maitro protects applications, venture briefs, member records, and commercial terms with scoped access, limited sub-processors, conflict review, incident routes, and clear current-vs-roadmap labels.

Current controlsMumbai-region postureSub-processors listedSOC 2 targetVulnerability disclosureQuality gate

Claim discipline

Premium does not mean reckless.

This page separates current controls, roadmap targets, illustrative tools, gated economics, and agreement-controlled terms so senior leaders can evaluate Maitro without mistaking posture for guarantee.

Current policy

No resale

Maitro should say no data resale, not blanket no-sharing. Limited vendors support core operations.

Careful wording

Primary India posture

Production hosting is described as India/Mumbai posture. Global sub-processors mean absolute residency language is avoided.

Planned

SOC 2 target

SOC 2 Type II is roadmap language only until a third-party report exists.

Current vs target

Security posture matrix

Each control is labeled by implementation posture so reviewers can distinguish production reality from roadmap.

AreaCurrent / target postureStatusClaim note
EncryptionTransport encryption is enforced at the web edge. Application-level encryption exists for selected sensitive records.Source-neededAES-256 at rest and TLS 1.3-only wording should stay source-needed until infrastructure evidence is attached.
Access controlAdmin surfaces use authenticated access and role checks where implemented.Current controlLeast-privilege and hardware-key MFA remain policy targets unless operator evidence is linked.
Logging and auditKey APIs write structured logs and selected workflows write audit rows.Current controlPublic copy should not imply every operator action is fully automated and audited until coverage is verified.
Sub-processorsLimited vendors support hosting, email, payments, auth, analytics, anti-bot, and error telemetry.Current controlUse limited sub-processors under policy controls; avoid blanket no-sharing language.
SOC 2SOC 2 Type II is not presented as certified.PlannedSOC 2 readiness and audit windows are roadmap targets until a report exists.
Incident responseSecurity contact route exists. Incident handling follows legal and policy requirements.Policy targetAvoid hard universal 72-hour user notification promises.

Sub-processors

Limited vendors, listed plainly

The right trust posture is limited sub-processors under policy controls, not a blanket no-third-party claim.

VendorPurposeData categoryRegionStatusNotes
Hostinger KVMApplication hostingApplication, member, and operational recordsMumbai / India postureCurrentPrimary production hosting. Exact backup region should be founder/security-confirmed.
CloudflareDNS, CDN, DDoS protection, Turnstile anti-botNetwork metadata, anti-bot tokens, request metadataGlobal edgeCurrentDo not claim absolute India-only residency while global edge services are used.
BrevoTransactional and newsletter emailEmail address, message metadata, transactional contentEU / vendor-controlledCurrentEmail implementation imports Brevo client.
RazorpayPayment processingCheckout, payment, invoice, and payment confirmation dataIndia / vendor-controlledCurrentMaitro does not receive full card numbers.
ClerkAuthentication and session managementIdentity, email, session tokensUS / vendor-controlledCurrentUsed on authenticated surfaces. Public pages may set no cookies before sign-in.
Cal.com or CalendlyOffice-hours schedulingCalendar metadata and booking detailsVendor-controlledConfigured path variesBook route supports provider-aware embeds. Avoid naming one exclusive provider in policy copy.
Sentry-compatible telemetry / GlitchTipError and performance telemetryError metadata, route, runtime contextConfigured environmentCurrent when DSN configuredTelemetry should be scrubbed for personal data where practical.
Anthropic via internal AI proxySpotlight content assistance and internal drafting workflowsLimited non-PII content artifacts where configuredExternal dependencyCurrent for selected pipelinesDo not claim application content is used for model training. Do not send secrets or unnecessary PII.
Conflict review

Conflict review is not perfect clearance.

Maitro can review submitted context against active and historical engagements, then recuse, carve out, or decline where needed. The process cannot guarantee employer IP clearance, and applicants may need independent counsel.

Incident response

Incident handling follows law, contract, and policy.

  1. Detect and record the event
  2. Triage scope, systems, and data categories
  3. Contain affected access or infrastructure
  4. Assess legal, privacy, and customer impact
  5. Notify where required by law, contract, or policy
  6. Remediate root cause and preserve evidence
  7. Run a post-incident review where applicable
Vulnerability disclosure

Responsible disclosure route

Email security@maitro.tech with reproduction steps and impact. Public researcher legal-protection, bug bounty, credit-page, or similar program language should not be shown unless counsel approves and the program is operational.

Quality gate

80-point gate as internal checklist

The quality gate is best described as an internal launch-readiness checklist unless automated evidence is published. It is not a certification or third-party audit.

FAQ

Security FAQ

Where is data hosted?

Maitro presents a primary India/Mumbai hosting posture, with limited sub-processors that may operate outside India. Do not interpret this as every byte staying in India.

Do you train AI on application content?

No public policy should say application content is used for model training. AI-assisted workflows must use minimized, non-secret content where configured.

Is SOC 2 live?

No. SOC 2 Type II should be treated as a planned or target control until a report is actually live.

How do I report a vulnerability?

Email security@maitro.tech with scope, reproduction steps, and impact. Do not include secrets, unrelated personal data, or public disclosure before triage.

Security route

Report vulnerabilities directly.

Send security issues to the dedicated route with reproduction steps. Keep secrets out of reports unless necessary for triage.

Maitro uses only strictly necessary session cookies and privacy-first, cookieless analytics. No advertising cookies are set. See our Cookie Policy.