Identity and authorization
Required multi-factor authentication, explicit role and grant management, firm and household scope, and database row-level security reinforce least privilege.
Trust center
Our trust program brings architecture, access controls, privacy, operational discipline, and evidence together. Public information is available here; appropriate detailed materials can be shared with customers and reviewers through a controlled request.
Required multi-factor authentication, explicit role and grant management, firm and household scope, and database row-level security reinforce least privilege.
Encryption, private database access, managed secrets, narrowly scoped runtime roles, and environment separation reduce exposure of sensitive financial data.
Automated tests and security scans, reviewed infrastructure plans, immutable image digests, migration gates, and post-release checks support accountable delivery.
Application code is scanned with Semgrep Community Edition whenever changes target the development or production branches and every Monday at 16:17 UTC. Dependency, secret, infrastructure-as-code, and container scans run in the same required CI program.
Transactional application audit events, deployment evidence, access reviews, and documented operating procedures are designed to make control performance verifiable.
We limit collection and access to service, security, legal, and customer-directed needs. We do not sell personal information or use it for behavioral advertising.
Report a suspected vulnerability to security@mohantechnology.com. Please do not include customer data, credentials, or exploit details in an unencrypted first message.
MFA is building and operating a control program aligned to the needs of regulated financial-services customers and a SOC 2 readiness process. This page does not claim a certification, audit opinion, regulatory approval, or guarantee of compliance. Current reports, assessment status, exceptions, and detailed control evidence are disclosed only when verified and appropriate for the requesting party.
Have a security question?
We will route customer questionnaires, due-diligence requests, and responsible disclosures to the right owner.