Trust & Security
Last updated: July 31, 2026
MantisOps builds security and IT-operations tools that connect deeply to customer infrastructure — vulnerability scanning (Mantis360), remote monitoring and management (MantisRMM), and network monitoring (MantisNMS). We hold ourselves to a security bar consistent with that access. This page describes how we protect your data and the practices behind our platform.
Architecture and data isolation
- Infrastructure. The platform runs on Cloudflare's global network — Workers for compute, D1 for databases, R2 for object storage, and KV for configuration — with Cloudflare's DDoS protection and edge security in front of every request.
- Per-tenant isolation. Each customer is provisioned with dedicated, isolated storage: a per-tenant database and a per-tenant object-storage bucket. Customer operational data is not commingled across tenants. Tenant isolation is a core contractual and architectural commitment, not a best-effort setting.
- Within-tenant separation. For customers who manage multiple companies (for example, MSPs), each company's data is scoped and access-controlled within the tenant.
Encryption
- In transit. All connections between your browser, our agents/probes/collectors, and our platform use TLS 1.2 or higher.
- At rest. Customer data stored in our databases and object storage is encrypted at rest by the underlying platform.
- Secrets. Sensitive credentials you store for monitoring (for example, SNMP or device credentials) are encrypted with authenticated encryption before storage and are used only to perform the monitoring you configure.
Access control and authentication
- Multi-factor authentication. Accounts support MFA at login, by authenticator app (TOTP) or emailed one-time code.
- Single sign-on. Enterprise single sign-on (SSO/OIDC/SAML) is supported across the product suite, with a shared, secure session across MantisOps applications.
- Role-based access control. Granular, role-based permissions govern what each user can see and do, enforced at the API — not just hidden in the interface.
- Least privilege internally. MantisOps personnel access customer data only as needed to operate and support the Services.
Agent, probe, and collector security
- Our agents, probes, and collectors communicate with the platform over authenticated, encrypted channels using per-device tokens.
- Our macOS software is code-signed and notarized by Apple; our Windows and Linux binaries are distributed through controlled release channels with versioned, integrity-checked updates.
- Software is installed only on systems you own or are authorized to manage. You control what data is collected, and you can uninstall at any time.
Data handling, retention, and deletion
- We collect the operational data described in our Privacy Policy to provide the Services, and we do not sell your data or use your infrastructure data to train AI models.
- Remote-session frames are streamed in real time and are not retained.
- On termination, we delete Customer Data within 30 days, except where retention is required by law. Our deletion window is deliberately short.
- Data may be stored and processed in the United States and the European Union on Cloudflare infrastructure.
Resilience and recovery
- Our storage platform provides durable, replicated storage with point-in-time recovery capability.
- We maintain documented disaster-recovery and backup procedures and periodically review our recovery posture.
Vulnerability disclosure
We welcome reports of security issues in our products and platform. To report a vulnerability, email security@mantisops.net. We do not permit unauthorized security testing of our platform or infrastructure (including pointing our own products at it) — see our Abuse & Restricted Use Policy.
Incident response
If we become aware of a security incident affecting your personal data, we notify affected customers without undue delay — with a description of the incident, the data involved, the steps we are taking, and recommended actions — consistent with our Data Processing Agreement (which commits to breach notification within 72 hours) and applicable law.
Sub-processors
We use a small set of vetted sub-processors (including Cloudflare for infrastructure and Stripe for payment processing). The current list is published at mantisops.net/legal/sub-processors and mirrored in our Privacy Policy. We provide advance notice of new sub-processors and an opportunity to object, as described in our Data Processing Agreement.
Privacy and compliance
- We support customer compliance with the GDPR (via our Data Processing Agreement and EU Standard Contractual Clauses for data transfers) and the CCPA/CPRA (see the California Privacy Rights section of our Privacy Policy).
- Formal third-party security certifications are on our roadmap; this page describes our current practices and is not a certification.
Contact
Security questions or reports: security@mantisops.net
General support: support@mantisops.net
MantisOps, LLC · 6650 Rivers Ave., Suite 100 · Charleston, SC 29406
← Back to MantisOps