Mantle
Home Log in

Mantle

Trust Center

Last updated 31 July 2026

Mantle is built for financial advisers who trust us with their most sensitive client information — health, income, superannuation, insurance. This page describes the controls we have in place to protect that data, the third parties that process it on our behalf, and how you can reach us if something concerns you.

Where the data lives

Mantle runs on infrastructure in Sydney, Australia. Client data stays in Australian data centres end-to-end — it never leaves the region for the primary app, database, or file storage.

App hosting

DigitalOcean App Platform · Sydney (SYD1)

Database

Supabase Postgres · ap-southeast-2 (Sydney)

File storage

Supabase Storage · Sydney region

AI processing

AWS Bedrock · ap-southeast-2 (Sydney)

Firm isolationLive

Mantle is multi-tenant — multiple firms share one platform. Client data is isolated at the database level using Postgres row-level security (RLS): every table that carries client information has policies that block cross-firm reads and writes even in the event of an application bug. A firm's users can only see their own firm's clients, tasks, policies, meetings, documents, and audit history.

  • Every User and every ClientRecord carries a firm column.
  • RLS policies enforced on all 40 tables that hold firm data.
  • Cross-firm visibility only for a designated master administrator, gated by session-level override + audit log entry.

EncryptionLive

  • In transit: HTTPS-only across all origins. HSTS preload eligible. TLS terminated at the DigitalOcean edge and re-encrypted for internal calls.
  • At rest — DB: Supabase Postgres encrypts data-at-rest at the storage volume level (AES-256).
  • At rest — sensitive tokens: Third-party OAuth tokens (Gmail, Outlook, Dropbox, Microsoft Graph, TOTP secrets) are additionally encrypted at the application layer using Fernet (AES-128-CBC + HMAC-SHA256) with a rotating master key held in a secrets manager, not in code.
  • At rest — files: Client documents in Supabase Storage inherit storage-volume encryption.

Authentication & access controlLive

  • MFA available on every account — TOTP (authenticator app), email OTP, and one-time recovery codes. Administrators are provisioned with a TOTP secret and recovery codes at account creation.
  • Password hashing: Werkzeug pbkdf2-sha256 with per-user salt. Raw passwords are never stored or logged.
  • Rate limiting: 5 failed logins per 10 minutes triggers a 15-minute IP lockout. 10 failed profile-link attempts per 15 minutes triggers a 30-minute IP lockout.
  • Session management: 24-hour absolute + idle session lifetime. Every user has a "sign out everywhere" control that force-invalidates all active sessions.
  • Role separation: Firm users, firm administrators (FULL_ACCESS), and master administrators are three distinct roles with cascading permissions.
  • Password reset: Self-service via email link. Only the SHA-256 hash of the reset token is stored server-side; tokens expire after one hour and are consumed on first use.

Audit loggingLive

Every write to the platform generates an audit-log entry with the actor's username, the client folder affected, the type of change, and a structured JSON diff of what changed. Authorisation failures (cross-firm access attempts, admin-route probes) are logged as authz_denied events.

  • Audit trail retained indefinitely for the life of the account.
  • Weekly encrypted export to an off-server Dropbox account so the trail survives a hosting-provider failure.
  • Firm administrators can view the audit log for their firm; the master administrator can view all firms.

AI processingLive

Mantle uses Anthropic Claude models via AWS Bedrock (Sydney region) for generation tasks like drafting emails, statements of advice, and client-facing summaries. Under our Bedrock agreement:

  • No training on customer data. Content sent to Bedrock is not used to train Anthropic's or AWS's models.
  • Regional processing. Requests stay within AWS ap-southeast-2 (Sydney).
  • Kill switches. An operator can disable all AI calls instantly via an environment variable if a runaway usage pattern is detected.
  • Circuit breaker. Automatic 60-second cool-off after 5 consecutive Anthropic failures — users see a graceful "AI unavailable" message rather than hanging requests.
  • Compliance detectors. Every AI output is run through a rule catalogue (banned phrases, insurer-naming rules, date-hallucination guards, financial-figure validation) before it can be sent to a client.

Backups & recoveryLive

  • Database: Supabase performs daily automated backups of the Postgres cluster.
  • Audit log: Weekly encrypted CSV export to a separate off-server Dropbox account.
  • Files: Client documents stored in Supabase Storage with automatic replication.
  • Recovery target: Restore-from-backup exercises run periodically. Documented recovery time objective (RTO): under 4 hours. Recovery point objective (RPO): under 24 hours.

AvailabilityLive

  • DigitalOcean auto-restart on container failure.
  • Per-request query-count instrumentation to catch performance regressions before they affect users.
  • Structured logging to Sentry for exception tracking + AWS CloudWatch for latency dashboards.
  • Public status page: coming soon.

Subprocessors

Mantle uses the following third parties to process customer data on our behalf. Each has a data processing agreement in place with Mantle and has been evaluated for security posture.

ProviderPurposeDataRegion
DigitalOcean, LLCApplication hostingAll app traffic + logsSydney, AU
Supabase Inc.Postgres database + file storageAll client records, files, audit trailSydney, AU
Amazon Web Services (AWS Bedrock)AI model inference (Anthropic Claude)Content sent to AI generation routesSydney, AU
Postmark (ActiveCampaign)Transactional email deliveryOutbound email metadata + bodyUnited States
Google Cloud (Gmail API)Per-user Gmail integrationUser-authorised inbox reads + sent-folder writesGlobal (Google)
Microsoft (Graph API)Per-user Outlook / Calendar integrationUser-authorised inbox + calendar reads/writesGlobal (Microsoft)
Dropbox, Inc.Per-firm file sync + audit-log backupClient documents synced by the firm; encrypted audit exportsUnited States
SentryApplication exception trackingError traces + request metadata (no client data)United States
Cloudflare, Inc.DNS + CDN edgeRequest metadata; TLS termination at the edgeGlobal (Cloudflare)

This list is updated when subprocessors change. Firms are notified in advance of any material change.

Compliance posture

  • Australian Privacy Act 1988 (APP compliance)Live — Mantle handles personal information consistently with the Australian Privacy Principles. See our privacy policy for details.
  • Essential Eight self-assessmentMaturity Level 1 — Mantle assesses itself against the Australian Cyber Security Centre's Essential Eight framework. Current maturity: Level 1 across all eight controls, targeting Level 2 by Q1 2027.
  • SOC 2 Type 1Under evaluation — Mantle is evaluating a formal SOC 2 compliance program. Please contact us if you require SOC 2 attestation to pilot Mantle at your firm — we'll discuss timeline based on your needs.
  • GDPRNot sought — Mantle serves the Australian market. Firms with EU data-subject exposure should contact us directly to discuss requirements.

Security incidents

In the event of a security incident affecting customer data, affected firms are notified without undue delay and no later than 72 hours after we become aware of the incident. Notifications include:

  • Nature and scope of the incident;
  • Categories of data affected;
  • Actions taken to contain and remediate;
  • Recommended actions for the affected firm.

Australian firms are also supported through their obligations under the Notifiable Data Breaches scheme where applicable.

Reporting a vulnerability

Security researchers and customers who believe they've found an issue should follow our security policy for responsible-disclosure steps and safe-harbour terms.

For all other security enquiries, contact [email protected].

Contact

Mantle
Operated by Square Peg Financial Pty Ltd (ABN 37 551 147 233)
Suite 201, 429 Bay Street, Brighton VIC 3186
[email protected]

On this page

Where the data lives Firm isolation Encryption Authentication & access Audit logging AI processing Backups & recovery Availability Subprocessors Compliance posture Security incidents Reporting a vulnerability Contact
© 2026 Mantle · Home · About · Pricing · FAQ · Security · Privacy · Terms · AI · Contact
Mantle does not hold an Australian Financial Services Licence and does not provide financial product advice. Mantle is a productivity tool for licensed advisers.