trust & security

A security product, built like a security company.

MentatNOC touches camera fleets, credentials, and physical security infrastructure. It is designed and operated to the same standard it asks fleets to meet: per-person access, two-person approval, and evidence for every action.

platform security

How the platform protects what it touches.

These practices apply across every tier, from monitoring to managed actions to compliance reporting.

Per-person accounts

Every user signs in with an individual account. No shared logins, ever.

Role-based access

Client, integrator, and operator tiers are kept separate, each scoped to what that role needs to see and do.

Maker-checker approval

High-risk actions require two people: one to request the action, a different person to approve it.

Hash-chained audit log

Every privileged action writes to an append-only, hash-chained log with immutable (WORM) retention.

Vaulted secrets

Credentials and secrets live in a managed vault. They never appear in logs.

Encrypted transport

Every connection, from device to dashboard, runs over encrypted transport.

Immutable backups

Backups are immutable, and restores are drilled, not assumed.

Staged rollouts

Changes ship in waves with health checks between them and automatic rollback on failure.

attestation

Independent verification.

MentatNOC is pursuing SOC 2 attestation; reports will be published on this page when issued.

reporting

Report a security concern.

If you find something that looks like a security issue in the platform, tell us.

see it running

See the compliance layer in action.

Walk through the fleet health board, a managed action, and the evidence it leaves behind.