MAVEL.AI
API + MCP
Security & data protection

Built on public answers. Run on certified rails.

Mavel analyses publicly observable AI answers — the product needs none of your customer data, PII or internal systems to work. This page states exactly how the data we do hold is stored, where it lives, who processes it, and honestly where our own compliance roadmap stands.

Data residency

Your region, your choice — end to end.

Residency isn't a footnote here; it's architecture. You choose your workspace region at signup and it does not change without your action.

EU workspaces

Stored and processed in EU infrastructure end to end: database in Neon's EU region (AWS eu-central-1, Frankfurt), application serving on Vercel's EU regions, object storage in Cloudflare R2 (EU jurisdiction).

US workspaces

The same architecture in US regions: Neon US database, US application serving and storage. Crawling of AI engines routes by target market independently of where your workspace lives.

Infrastructure certifications (our providers', not ours — details below): VERCEL · SOC 2 · ISO 27001 NEON/AWS · SOC 2 · ISO 27001 CLOUDFLARE · SOC 2 · ISO 27001 · PCI STRIPE · PCI DSS L1
Compliance status

The honest dashboard.

One row per framework, with its real status. No badge walls, no borrowed certificates.

GDPRCompliant

We operate as a processor for workspace data under GDPR. EU data residency available end to end; standard contractual clauses cover any transfer to non-EU subprocessors.

DPAAvailable

A data processing agreement is available for business customers — request it at the contact below.

SOC 2Not yet certified

Mavel does not currently hold its own SOC 2 attestation. It is on our roadmap; we will publish a date here when an auditor is engaged, not before.

ISO 27001Under evaluation

Being evaluated alongside SOC 2. Our infrastructure providers hold it (see below); we do not claim it as our own.

Infrastructure

Certified rails, scoped honestly.

Mavel runs entirely on infrastructure that holds current, independently audited certifications. These are our providers' certifications, not ours — the distinction matters, and we state it plainly:

  • Vercel (application platform) — SOC 2 Type 2 attested, ISO 27001:2022 certified. Details at vercel.com/security.
  • Neon on AWS (databases, EU + US regions) — SOC 2, ISO 27001; AWS data centres additionally carry ISO 27001/27017/27018 and SOC 1/2/3.
  • Cloudflare R2 (object storage) — SOC 2 Type II, ISO 27001, PCI DSS.
  • Stripe (payments) — PCI DSS Level 1. Mavel never stores or even sees your card data.
Controls

The concrete practices.

  • Encryption — TLS 1.2+ for all data in transit; AES-256 encryption at rest on all databases and object storage.
  • Access control — role-based access inside workspaces; least-privilege and MFA for all internal administrative access.
  • Backups — continuous point-in-time recovery on all primary databases, tested restores.
  • Tenant isolation — workspace-scoped data access enforced at the query layer and continuously checked by static analysis in CI.
  • Retention & deletion — workspace data is deleted on contract end under your retention policy; deletion requests honoured per GDPR timelines.
  • If something goes wrong — confirmed incidents affecting your data are notified to you without undue delay, consistent with our GDPR processor obligations, with scope, impact and remediation stated plainly.
  • Vulnerability reports[email protected]. We read everything and respond to genuine reports.
AI data handling

What the models see.

Mavel's analysis runs large language models over publicly observable AI answers and public web sources — the same outputs any user of ChatGPT, Gemini, Claude or Perplexity can see — plus the brand context you configure (brand names, competitors, topics).

  • No training on your data — we use Anthropic, OpenAI and Google via their commercial APIs, which do not train on API data by default. We have not opted in to any data-sharing programme.
  • No PII required — the product needs no customer lists, analytics access, CRM connections or internal documents to function.
  • Provider terms, linked not asserted — each provider's API data-usage policy is the authoritative source: anthropic.com/legal, openai.com/enterprise-privacy, ai.google.dev/terms.
Subprocessors

Who processes what.

The full list, named and dated — not "industry-standard providers." Last updated: July 2026.

ProviderPurposeRegion
VercelApplication hosting & servingEU / US per workspace
Neon (AWS)Primary databasesEU (Frankfurt) / US per workspace
CloudflareObject storage (R2), CDN, ingestEU / US jurisdictions
StripePayments & billingEU/US (PCI DSS L1)
AnthropicLLM analysis (API, no training)US
OpenAILLM analysis (API, no training)US
GoogleLLM analysis (API, no training)US/EU
ResendTransactional emailUS
SentryError monitoring (no payload PII)US
PostHogProduct analyticsEU
Better StackLog management & uptimeEU
CrispSupport chatEU
Contact

Ask us anything specific.

Security reviews, DPA requests, data-flow questions: [email protected] — or route it through sales as part of an enterprise conversation. We answer the actual question rather than sending a boilerplate packet.

MAVEL.AI

The narrative layer of AI search. Win the story the model tells, not just the mention.

FREE GEO REPORT →
PLATFORM
AI VisibilityBrand PerceptionAgent Analytics
SOLUTIONS
For B2B SaaSFor E-commerceFor AgenciesAll solutions
RESOURCES
BlogGlossaryGEO ReportDocsResearch
COMPANY
PricingEnterpriseContactSecurity
© 2026 Mavel.ai
PrivacyTermsImprintCookies