Compliance

MitosSoft is committed to building products that meet the highest security and compliance standards. While we are not yet formally certified, our engineering practices, infrastructure, and processes are designed in alignment with industry-leading frameworks.

Compliance-Ready, Certification in Progress

We currently operate in alignment with these frameworks and are actively working toward formal certifications. Our goal is to provide the same level of trust and transparency as certified organizations while we complete the audit process.

Framework Alignment

Our products and processes are designed in line with the following standards.

Aligned

SOC 2 Type II

We follow SOC 2 principles across our infrastructure — security controls, access management, encryption, and monitoring are designed in line with Trust Service Criteria.

Aligned

ISO 27001

Our information security management practices follow ISO 27001 guidelines — including risk assessment, access controls, incident response, and continuous improvement processes.

Aligned

GDPR

We design our products with GDPR principles in mind — data minimization, purpose limitation, consent management, and right to erasure capabilities are built into our architecture.

Aligned

HIPAA

Our healthcare-facing products are built with HIPAA-compatible safeguards — data encryption at rest and in transit, audit logging, and role-based access controls.

Aligned

KVKK

We operate in accordance with Turkey's Personal Data Protection Law — data processing principles, cross-border transfer safeguards, and data subject rights are integrated into our workflows.

Aligned

PCI DSS

MitCart's payment flows are designed following PCI DSS best practices — tokenized card handling, encrypted transmission, and secure payment gateway integrations.

Security Practices

Regardless of certification status, these practices are embedded in every product we build.

Encryption

All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Database-level encryption for sensitive fields.

Access Control

Role-based access with least-privilege principle. Multi-factor authentication support. Session management and audit logging.

Data Isolation

Multi-tenant architecture with strict tenant isolation. Row-level and column-level security policies prevent cross-tenant data access.

Incident Response

Documented incident response procedures. Real-time monitoring and alerting. Post-incident review and continuous improvement.

Data Retention

Configurable data retention policies. Automated data purge workflows. Right to erasure support across all products.

Vendor Management

Third-party services are evaluated for security posture. Sub-processor agreements maintained for data handling transparency.

Certification Roadmap

We are actively working toward formal certifications for the following standards.

SOC 2 Type II AuditPlannedFormal third-party audit and certification
ISO 27001 CertificationPlannedIndependent ISMS certification
KVKK VERBİS RegistrationPlannedOfficial registry completion
PCI DSS Level 1 AssessmentPlannedQualified Security Assessor engagement

Questions About Our Compliance Posture?

We're happy to walk you through our security practices, share our compliance documentation, or discuss how we can meet your organization's requirements.

Contact Compliance Team