Mimecast's AI Vulnerability Intelligence & Attack Surface Management
Mimecast Logo

Trust Center

background-image
Start your security review
View & download sensitive information
Ask for information
ControlK

Trust Center

Data protection regulations in general are designed to protect the personal data of individuals and impose obligations on organizations that collect, process, and store such personal data. These obligations apply to both our customers and Mimecast. We take our obligations under these data protection regulations (such as GDPR, CCPA, POPIA and PIPEDA) governing the services we provide seriously.

We are always reviewing our products and services and making enhancements to help support our customers’ data privacy compliance journey. We also commit ourselves to data protection through our Data Processing Addendum which is available to our customers.

Scroll down this page for information cards including:

  • Certification and Attestation reports (security packs)
  • Data Processing Addendum
  • AI Development Pledge
  • Processing details
  • Technical and Organizational Measures
  • Sub-processors
  • Accessibility Statement
  • Privacy Statement

We're here to help. Contacts us at: certificationqueries@mimecast.com.

Documents

Featured Documents

COMPLIANCEISO 14001:2015

Trust Center Updates

Mimecast's AI Vulnerability Intelligence & Attack Surface Management

Copy link
General

Mimecast actively monitors coordinated disclosure programs from leading AI developers, including Anthropic, as well as disclosures from multiple sources across the frontier AI ecosystem.

We maintain a comprehensive Vulnerability and Attack Surface Management program that includes, but is not limited to, threat intelligence, industry-leading detection and assessment tools, a bug bounty and vulnerability disclosure program, and penetration testing and red team exercises — all augmented by AI tooling and best practices, and all integral to our Secure Software & Systems Development Lifecycle (SSDLC) program. Vulnerabilities are ranked by severity and exploitability and managed accordingly.

This is part of our standard operating process and further strengthens — but does not alter — how we handle and report incidents.

Built onSafeBase by Drata Logo