Security & Trust
Security & Trust
How we secure access, protect personal data, and operate — with verified founder credentials and standards from our Engagement Terms and Data Processing Addendum.
We also help clients prepare for SOC 2 and ISO 27001 readiness. Framework reports for client environments are shared under contract when available — those are client attestations, not Mugen company seals.
Licenses & certifications
Held by Sahar Mana, Co-founder · Operations, Identity & Compliance.
PeopleCert
ITIL 4 Foundation Certificate in IT Service Management
Microsoft
GitHub Foundations
Google
Associate Google Workspace Administrator
Apple
Apple Certified Support Professional
How we handle access
We never share passwords or keys in plain text over email, chat, or phone. Access is granted through a shared password manager / vault, single sign-on (SSO), or temporary accounts with only the minimum permissions needed. We use multi-factor authentication (MFA) on every administrative login. When an engagement ends, we promptly remove or hand back all access we were given.
Change control & auditability
We follow written procedures for making changes and granting access. Where the platform supports it, we keep an audit log of actions on critical systems so changes can be traced to who made them and when.
Technical & organisational measures
Proportionate to risk, we apply: least-privilege and time-boxed access; secrets in a vault with rotation on personnel or engagement changes; encryption in transit (TLS) and at rest where supported; logical segregation of client environments; no reuse of client data for other clients; logging and monitoring on critical systems; up-to-date, protected endpoints for personnel accessing personal data; confidentiality undertakings; and a documented incident-response process.
AI-assisted tools
We use professional tools, including AI-assisted tools, to work efficiently. We make best (maximum) efforts not to input a client’s personal or confidential data into such tools, and prefer tools that do not use submitted data to train their models. Any tool that processes a client’s personal data is treated as a sub-processor under our Data Processing Addendum.
Personal data & breaches (client work)
Where we process personal data on a client’s behalf, the client is the controller and Mugen is the processor under Israel’s Protection of Privacy Law and, where applicable, the EU GDPR. Processing is governed by our Data Processing Addendum. We notify the client without undue delay and in any event within 72 hours of becoming aware of a personal-data breach affecting their data, with information reasonably available to help them meet their obligations.
Website transport & consent
mugensolutions.net is served over HTTPS with HSTS. Contact form submissions are accepted only over TLS-encrypted connections in production. Non-essential analytics and marketing scripts load only after you opt in via Cookie settings.
Client responsibility
Clients remain responsible for the overall security posture of their environment, including maintaining current backups and a tested recovery capability, except where backup/recovery is separately scoped with us.
Questions
For security or compliance inquiries, email sahar@mugensolutions.net.