Aller au contenu

Trust Center

What Mithril (operated by Kotoba Labs Inc.) has in place for security, privacy and compliance, and what it has not yet obtained. Every row is generated from Mithril's GRC program record; the same evaluation is available machine-readably at /v1/security/grc/program/mithril.

This page is not a certification claim. "In force" is our own declaration, not a third-party attestation. Evaluated at 2026-09-25T04:23:53.837Z.

Legal documents (drafts pending counsel review)

Certifications

Mithril holds no security or privacy certification and no third-party attestation today.

  • SOC 2 Type II: not yet obtained.
  • ISO/IEC 27001: not held.
  • PCI DSS: card data is handled by Stripe and never reaches Mithril (PCI scope delegated to Stripe).

The /secure/ table describes automated controls mapped to frameworks; it is not a certification, audit or attestation of conformance.

Contact

Target market

Mithril's certification target is the US federal market (FedRAMP). ISMAP is not pursued at this time.

Baseline disclosures

Baseline disclosures
Item Status
Privacy policy Not yet
Terms of service Not yet
Subprocessor list (with change notice) Not yet
Data processing agreement Not yet
security.txt at /.well-known/security.txt In progress
Vulnerability disclosure policy In progress
Data residency statement (where data is stored and processed) Not yet

Operational disclosures

Operational disclosures
Item Status
Trust center In progress
Service level agreement Not yet
Penetration test report summary (third party) Not yet
VPAT / Accessibility Conformance Report Not yet

Third-party assessments and certifications

Third-party assessments and certifications
Item Status
SOC 2 Type I report Not yet
SOC 2 Type II report Not yet
ISO/IEC 27001 certificate Not yet
ISO/IEC 42001 certificate (AI management system) Not yet
ISMAP registration Not pursued
FedRAMP authorization Not yet

Next

Items whose prerequisites are met and that can start now, in recommended order:

  1. Privacy policy
  2. Terms of service
  3. Subprocessor list (with change notice)
  4. security.txt at /.well-known/security.txt
  5. Vulnerability disclosure policy
  6. Penetration test report summary (third party)