Security & Compliance
Enterprise-grade security. Built in from day one.
Infrastructure Security
- Hosted on AWS infrastructure
- VPC isolation and private networking
- Multi-region data redundancy
- 24/7 infrastructure monitoring
Data Protection
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Zero data retention policy
- Automatic data purging
Access Control
- Single Sign-On (SSO) support
- Multi-factor authentication
- Role-based access control
- Comprehensive audit logging
Compliance
- SOC 2 Type II certified
- Designed for GDPR compliance
- Designed for CCPA compliance
- Regular third-party security audits
Security-First Architecture
We handle sensitive M&A data. We build security into every layer of our platform. Our infrastructure meets the rigorous requirements of SOC 2 Type II certification.
We never train on your documents. Your data stays yours. Purged automatically after processing.
Frequently Asked Questions
Common questions about Mage Security
No. Mage never trains on your documents, client data, or any user content. Your data is used solely to provide the analysis service and is never used for model training, fine-tuning, or any other purpose. This is a core architectural principle, not just a policy.
Mage maintains a zero data retention policy. Documents are processed in isolated environments and automatically purged after analysis is complete. We do not store your documents beyond the time necessary to deliver results.
Mage has implemented SOC 2 Type II security controls covering availability, confidentiality, and data protection. We maintain enterprise-grade infrastructure with comprehensive access controls, audit logging, incident response procedures, and regular security assessments.
Mage uses AES-256 encryption for data at rest and TLS 1.3 for data in transit. All document processing occurs in encrypted, isolated environments. These are the same encryption standards used by major financial institutions.
Yes. Mage supports Single Sign-On (SSO) integration with major identity providers including Okta, Azure AD, and Google Workspace. We also support SAML 2.0 for custom SSO configurations. MFA is available for all accounts.
Mage is designed to protect attorney-client privilege. We process documents in isolated environments, maintain strict access controls, and never share data with third parties. Our zero retention policy means no privileged content persists after processing.
Report a Security Issue
We take security seriously. If you discover a vulnerability or have a security concern, please let us know.