Mentorloop is Cyber Essentials certified and GDPR compliant, with data hosted on Amazon and Google infrastructure across Australia, the UK, and the US. This page covers all security, privacy, and compliance documentation.
Governance, risk management, and compliance
Security certifications
Mentorloop is Cyber Essentials certified, verified by external auditors. All data is encrypted in transit (TLS 1.2 or above) and at rest. The platform runs on Amazon and Google cloud infrastructure, all with secure, audited data centers.
We work with third-party security services and network scanning tools to reduce vulnerabilities. To express interest in ISO 27001 or SOC 2 compliance documentation, email security@mentorloop.com.
GDPR compliance
Mentorloop is fully GDPR compliant and registered with the ICO, the UK's Data Protection Regulator. We have published our Data Processing Addendum and maintain a register of third-party subprocessors.
More detail is available in our article: GDPR — How We've Handled It.
B Corp certification
Mentorloop is a Certified B Corporation, reflecting our commitment to using business as a tool for positive change and holding ourselves accountable to that standard.
Corporate Social Responsibility (CSR) policy
Our CSR Policy covers our supplier code of conduct, environmental responsibility, community and social responsibility, ethical conduct, and anti-bribery and corruption statement.
Business continuity and disaster recovery
Mentorloop's Business Continuity & Disaster Recovery plan identifies critical business activities, defines a tested incident response process, and documents recovery procedures. It covers critical activities, incident response, key contacts, and facility unavailability.
Risk management
Our risk management process is developed in accordance with ISO 31000:2018 and follows five steps: identify, analyse, control, monitor & review, and report.
Data privacy
Mentorloop is compliant with the Australian Privacy Act 1988, including the Australian Privacy Principles (APPs).
Privacy policy
Our Privacy Policy sets out how Mentorloop collects, uses, stores, and discloses personal information, and how individuals can exercise their rights. It covers collection, cookies, use, third-party disclosure, data retention, international transfers, and complaints.
Staff information security policy
Our Staff Information Security Policy applies to all employees, contractors, and anyone with access to Mentorloop systems or data. Access follows the principle of least-privilege. All staff complete InfoSec training on employment and every six months.
Security
Security policy
The Security Policy covers identity management, access controls, data center management, audit logging, OS maintenance, data segregation and classification, backups, and vetting of staff and third parties.
Security incident response
Our Security Incident Response Plan covers how we identify, investigate, contain, recover from, and disclose security incidents. Web application penetration testing is performed annually by an authorised third party.
Data hosting and cloud architecture
Application data centers are located in Sydney (AU), London (UK), and Ohio (US). A program is hosted in the data center matching the customer's primary location. All data in transit uses TLS 1.2 or above; all application data is encrypted at rest. The platform is protected by a Web Application Firewall (WAF).
To request the full cloud architecture document, contact support@mentorloop.com.
Application
Mobile app
Mentorloop has native mobile apps for iOS and Android, so participants can manage their mentoring on the go. Download from the Apple App Store or the Google Play Store.
Authentication methods
Mentorloop supports password login, social sign-on with Google and LinkedIn, and single sign-on via SAML and OIDC. Standard SAML/OIDC SSO configurations are with Microsoft Entra ID and Okta - read more about Single sign-on with Mentorloop. Mentorloop staff administrator access is secured with MFA. Participant MFA can be enforced as part of an SSO configuration if required.
Apps and integrations
Mentorloop integrates with calendar platforms (Google, Outlook, Apple iCloud, Exchange), video conferencing (Zoom and Microsoft Teams), and Slack for notifications. HRIS and CRM integrations (Salesforce, HubSpot, SAP SuccessFactors, BambooHR, Oracle) are available on Enterprise. See the full Apps & Integrations list.
Accessibility (WCAG compliance)
Mentorloop is partially compliant with WCAG 2.2 Level AA. Some platform areas meet or exceed AAA standard. If you have specific accessibility requirements, contact your Mentorloop Customer Success Manager or our support team. See also our Accessibility Statement.
Age suitability
Mentorloop is designed for use in professional and educational contexts. Access is invitation-only, managed by the organisations that run programs on the platform. Organisations are responsible for ensuring participants meet any relevant age requirements. See our Age Suitability and User Safety article for full details.
Minimum IT requirements
See the Minimum IT Requirements article for supported operating systems, browsers, and other IT considerations.
Third-party subprocessors
To maintain GDPR compliance and manage risk, Mentorloop maintains a register of third-party subprocessors, including their own compliance status with relevant privacy legislation.
Usage terms, policy, and guidelines