Trust and security
How we protect your data.
Our information security management system is documented against the structure of ISO/IEC 27001:2022. What follows is the public summary of that document.
Control domains
Scope and management leadership
The ISMS scope, interested parties, management responsibilities and accountability are documented. A CISO is appointed.
Risk management
A cycle of identifying, assessing and mitigating risk, with residual risk formally accepted by management.
Data centre and infrastructure
Attack prevention, detection and response; network and system hardening; administrative access restricted over VPN.
Access control
Role-based permissions, two-factor authentication, IP and location restrictions, and per-user unique links.
API security and logging
API key management, rate limiting, and audit logging with defined retention.
Confidentiality and encryption
TLS in transit, protection at rest, and key management.
Backup and continuity
Regular backups, restore testing, a standby server and defined availability objectives.
Incident management
Detection, response, customer notification procedures and post-incident improvement.
Third-party management
Supplier assessment, contractual requirements and subprocessor oversight.
Legal and regulatory compliance
Mongolian law together with international requirements such as GDPR.
Data subject rights
Procedures for receiving and processing access, correction and deletion requests.
Internal audit
The effectiveness of the ISMS is reviewed regularly and corrective action taken.
Documents and links
| Privacy policy | maildy.mn/legal/privacy ↗ |
| Terms of service | maildy.mn/legal/terms-of-service ↗ |
| Acceptable use policy | maildy.mn/legal/acceptable-use ↗ |
| GDPR | maildy.mn/gdpr ↗ |
| System status | maildy.mn/status ↗ |
| Data processing agreement (DPA) | Available on request |
Security enquiries
Procurement questionnaires, DPAs or vulnerability reports: [email protected]
