Give AI access without giving up control.

See exactly what your AI agents are doing, put people in the loop where it matters, and stay in control of usage and spend.

SOC 2Type II GDPRReady
Activity
SessionToolOwnerScopeStatusWhenOpen
May close reconciliation QuickBooks Ben Nathan read · 142 rows Running 2m ago
File invoice #4821 to Drive Google Drive Dana Cole write · 1 file Success 41m ago
Overdue account sweep Salesforce Mia Reyes read · 6 records Needs review 3h ago
Refund $2,410, ticket 8812 Stripe Dana Cole write · blocked Denied 3h ago
Weekly #finance digest Slack Ben Nathan write · 1 message Success Yesterday
EU contact export HubSpot Mia Reyes read · 0 rows Skipped Yesterday

Each session opens into its full trace, down to the approval that let it through.

You keep the keys, the logs, and the data.

Control

The tool’s owner grants access, per tool, at the scope they pick. Nothing widens on its own, and one click takes it back.

Visibility

Every run, tool call, and approval, logged in plain language your team can read without asking us.

Data protection

Encrypted in transit and at rest, isolated per workspace. Never sold, never shared, never used for training.

Reliability

Monitored around the clock. When something looks wrong, we say so, with a named owner and a written response path.

Nothing ships without your yes.

Reads run freely inside the scopes you grant. Everything else stops and waits for a yes.

  • See the exact change first

    The request names the tool, the account, and the precise edit.

  • You set the scope

    Once, for this task, or always for this tool. Revoke anytime.

  • A person signs off

    Flagged output goes to a reviewer, and the verdict lands on the run.

Can I run Send payment reminder?

Send payment reminder
Vendor
Northwind Traders, invoice #4821
Amount
$2,410.00, 14 days overdue
Account
QuickBooks · Finance workspace (read + write)

Minded only touches the account and scope shown above.

Hardened at every layer.

Encryption

  • TLS 1.2+ in transit
  • AES-256 at rest
  • Secrets in a managed vault, never in a prompt

Infrastructure

  • Cloud infrastructure with hardened defaults
  • Data isolated per workspace
  • Least-privilege service accounts, encrypted backups

Access control

  • OAuth first, so we never hold your password
  • Per-tool scopes, chosen by the tool owner
  • Single sign-on, revoke in one click

Your data works for you. Nobody else.

The list is short on purpose. If something is missing, ask and we will answer in writing.

  • Train a model on your data
  • Sell, share, or rent your data
  • Store your passwords
  • Touch a tool you have not connected
  • Reach across workspaces
  • Take a sensitive action with no approval on record

Answers for your security review.

Do you train models on our data?
No. Your data does your work and nothing else. It is never used for training, ours or anyone else’s, and never shared between workspaces.
Where do our credentials live?
Connections are OAuth-first, so in most cases we never see a password. Tokens and any keys you provide sit in an encrypted vault and are never written into a prompt.
What can Minded do without asking?
Read, within the scopes you granted. Writes, sends, and spends stop and ask first, and your answer is logged on the run.
Can we see what it actually did?
Yes. Activity lists every session with tool, owner, scope, outcome, and time, and each opens into the full step-by-step trace.
How do we revoke access?
Disconnect the tool in Minded, or revoke the grant in the tool’s own admin console. Both take effect immediately and stop running sessions.
Can we get your SOC 2 report?
Yes, under NDA. Write to security@minded.com and we will send the report, the DPA, and the current sub-processor list.
How do we report a vulnerability?
Email security@minded.com. We acknowledge every report, keep you posted through the fix, and credit you if you want it.