Trust Center
What Mithril (operated by Kotoba Labs Inc.) has in place for security, privacy and compliance, and what it has not yet obtained. Every row is generated from Mithril's GRC program record; the same evaluation is available machine-readably at /v1/security/grc/program/mithril.
This page is not a certification claim. "In force" is our own declaration, not a third-party attestation. Evaluated at 2026-09-25T04:23:54.003Z.
Legal documents (drafts pending counsel review)
- Privacy Policy
- Terms of Service
- Master Services Agreement
- Data Processing Addendum
- Subprocessors and data residency
- Acceptable Use Policy
Certifications
Mithril holds no security or privacy certification and no third-party attestation today.
- SOC 2 Type II: not yet obtained.
- ISO/IEC 27001: not held.
- PCI DSS: card data is handled by Stripe and never reaches Mithril (PCI scope delegated to Stripe).
The /secure/ table describes automated controls mapped to frameworks; it is not a certification, audit or attestation of conformance.
Contact
- Security and vulnerability reports: security@mithril.fund (vulnerability disclosure policy, security.txt)
Target market
Mithril's certification target is the US federal market (FedRAMP). ISMAP is not pursued at this time.
Baseline disclosures
| Item | Status |
|---|---|
| Privacy policy | Not yet |
| Terms of service | Not yet |
| Subprocessor list (with change notice) | Not yet |
| Data processing agreement | Not yet |
| security.txt at /.well-known/security.txt | In progress |
| Vulnerability disclosure policy | In progress |
| Data residency statement (where data is stored and processed) | Not yet |
Operational disclosures
| Item | Status |
|---|---|
| Trust center | In progress |
| Service level agreement | Not yet |
| Penetration test report summary (third party) | Not yet |
| VPAT / Accessibility Conformance Report | Not yet |
Third-party assessments and certifications
| Item | Status |
|---|---|
| SOC 2 Type I report | Not yet |
| SOC 2 Type II report | Not yet |
| ISO/IEC 27001 certificate | Not yet |
| ISO/IEC 42001 certificate (AI management system) | Not yet |
| ISMAP registration | Not pursued |
| FedRAMP authorization | Not yet |
Next
Items whose prerequisites are met and that can start now, in recommended order:
- Privacy policy
- Terms of service
- Subprocessor list (with change notice)
- security.txt at /.well-known/security.txt
- Vulnerability disclosure policy
- Penetration test report summary (third party)