Trust and security

How we protect your data.

Our information security management system is documented against the structure of ISO/IEC 27001:2022. What follows is the public summary of that document.

Control domains

Scope and management leadership

The ISMS scope, interested parties, management responsibilities and accountability are documented. A CISO is appointed.

Risk management

A cycle of identifying, assessing and mitigating risk, with residual risk formally accepted by management.

Data centre and infrastructure

Attack prevention, detection and response; network and system hardening; administrative access restricted over VPN.

Access control

Role-based permissions, two-factor authentication, IP and location restrictions, and per-user unique links.

API security and logging

API key management, rate limiting, and audit logging with defined retention.

Confidentiality and encryption

TLS in transit, protection at rest, and key management.

Backup and continuity

Regular backups, restore testing, a standby server and defined availability objectives.

Incident management

Detection, response, customer notification procedures and post-incident improvement.

Third-party management

Supplier assessment, contractual requirements and subprocessor oversight.

Legal and regulatory compliance

Mongolian law together with international requirements such as GDPR.

Data subject rights

Procedures for receiving and processing access, correction and deletion requests.

Internal audit

The effectiveness of the ISMS is reviewed regularly and corrective action taken.

Documents and links

Privacy policymaildy.mn/legal/privacy ↗
Terms of servicemaildy.mn/legal/terms-of-service ↗
Acceptable use policymaildy.mn/legal/acceptable-use ↗
GDPRmaildy.mn/gdpr ↗
System statusmaildy.mn/status ↗
Data processing agreement (DPA)Available on request

Security enquiries

Procurement questionnaires, DPAs or vulnerability reports: [email protected]