Access

Identity and authorization

Required multi-factor authentication, explicit role and grant management, firm and household scope, and database row-level security reinforce least privilege.

Data

Protected infrastructure

Encryption, private database access, managed secrets, narrowly scoped runtime roles, and environment separation reduce exposure of sensitive financial data.

Delivery

Controlled change

Automated tests and security scans, reviewed infrastructure plans, immutable image digests, migration gates, and post-release checks support accountable delivery.

Application security

SAST on changes and weekly

Application code is scanned with Semgrep Community Edition whenever changes target the development or production branches and every Monday at 16:17 UTC. Dependency, secret, infrastructure-as-code, and container scans run in the same required CI program.

Evidence

Auditable operations

Transactional application audit events, deployment evidence, access reviews, and documented operating procedures are designed to make control performance verifiable.

Privacy

Purpose and minimization

We limit collection and access to service, security, legal, and customer-directed needs. We do not sell personal information or use it for behavioral advertising.

Response

Responsible disclosure

Report a suspected vulnerability to security@mohantechnology.com. Please do not include customer data, credentials, or exploit details in an unencrypted first message.

Current posture

Claims should match evidence.

MFA is building and operating a control program aligned to the needs of regulated financial-services customers and a SOC 2 readiness process. This page does not claim a certification, audit opinion, regulatory approval, or guarantee of compliance. Current reports, assessment status, exceptions, and detailed control evidence are disclosed only when verified and appropriate for the requesting party.

Have a security question?

Start with the trust team.

We will route customer questionnaires, due-diligence requests, and responsible disclosures to the right owner.