Security

Security controls for a product trusted with customer conversations.

Mango processes business instructions, caller details, transcript text and operational records. Our controls are designed around tenant separation, least-privilege access, encryption, reviewability and a documented response when something goes wrong.

Encryption

Data is encrypted in transit using TLS 1.2 or later and encrypted at rest through the configured hosting and storage services.

Tenant isolation

Business knowledge and operational data are scoped by tenant, including isolated per-tenant knowledge indexes.

Access control

Administrative access uses least-privilege controls and multi-factor authentication, with secret management and logging around privileged systems.

Software assurance

Security practices include code review, dependency review, vulnerability scanning, patching and monitored production logging.

Incident response

A documented incident process supports investigation, containment, recovery and required customer or regulator notification.

Reviewable conversations

Customers can review stored transcript text, summaries and outcomes. Call audio is not stored by default.

Shared responsibility

Safe operation also depends on configuration.

Customers control the information Aimee receives, the rules she follows, who may access the account and which external services are connected. Keep account credentials private, enable the strongest authentication available, review scripts and knowledge regularly, and remove access when a team member no longer needs it.

The complete processing roles, technical and organisational measures, sub-processors and cross-border transfer terms are set out in the Data Processing Addendum. Personal-information practices are detailed in the Privacy Policy.

Responsible disclosure

Think you found a security issue?

Email security@mangoreceptionist.com with a clear description, the affected surface, steps to reproduce and any evidence that can be shared safely.

Do not access another customer's data, disrupt the service, use social engineering, exfiltrate unnecessary data or publish details before Mango has had a reasonable opportunity to investigate and address the report.