Skip to content

Security and data

Security, data and what MBI does with AI

Everything below is a control that exists today, described in the words a security review uses. Where a statement is contractual, the clause is linked. Nothing here is a plan.

Where the data is

Persistent customer content and the primary application data are hosted and stored in the European Union, with Hetzner Online GmbH as the hosting provider. Backups are encrypted and held in the same region.

Network transport is encrypted using current secure protocols, and stored data is encrypted where appropriate. The technical and organisational measures are enumerated in Annex B of the Data Processing Agreement rather than summarised loosely here.

Account isolation

What MBI learns while working for you is scoped to your account. Business descriptions, product descriptions, the source pool, the memory it keeps per competitor and per account, and everything in your briefs stay inside your account and are not pooled with any other account, including a competitor of yours.

There is no shared intelligence layer across customers, and no aggregate product built out of what customers upload. This is a design decision rather than a configuration option, so there is nothing to switch on.

What the AI does, and what it is given

MBI is an AI product end to end: source discovery, the weekly research, the judgement about what matters, the writing, and the handling of instructions you send by email. Inference runs at Anthropic PBC as a named subprocessor under Standard Contractual Clauses.

What you upload is used to research your market and for nothing else. It is not used to train a model.

  • Every finding carries a source link, so any claim can be checked rather than trusted.
  • Every signal is labelled confirmed, likely or speculative, so a hedge cannot read as a fact.
  • A quiet week produces a short brief saying so, rather than manufactured significance.
  • Nothing is researched until you have confirmed what MBI concluded about your business.
  • Replying to a brief reaches a person on our side, and every change made from an email comes back as a plain-language confirmation and lands in the audit log.

Subprocessors

The current register is published rather than supplied on request, and it lists the actual production vendors, not categories. Adding or replacing one does not amend the DPA; notice is handled under its Section 12.

SubprocessorPurposeRegionTransfer mechanism
Anthropic PBCAI inference for research, analysis and report writingUnited StatesStandard Contractual Clauses
Hetzner Online GmbHApplication hosting, database and encrypted backupsEuropean UnionNot required
Mailjet (Sinch)Transactional and report email deliveryEuropean UnionNot required
Stripe Payments Europe, Ltd.Payment processing and invoicingEuropean Union, with group processing outside itStandard Contractual Clauses

The register as at 10 August 2026. The authoritative copy, with the processing detail Annex C requires, is published with the Data Processing Agreement.

How sources are handled

MBI reads public, professional, B2B material: regulator filings, investor material and earnings calls, standards drafts, vendor release notes and pricing pages, tender portals, trade press with real reporters, and the public output of analysts and practitioners.

MBI does not scrape LinkedIn. The people who matter are followed through what they publish elsewhere. Every source in your pool shows its provenance, whether you added it or MBI found it, and you can pin a source so it is never retired or remove one outright.

Retention and deletion

Customer content is deleted or returned after termination in line with the DPA and MBI's deletion processes. Backup copies may persist for a limited period until normal backup rotation overwrites them; they stay protected and are not restored except for continuity, recovery or security purposes.

Recipients of a brief never hold an account and can unsubscribe themselves, because they never signed up to anything.

What MBI does not have yet

Stated plainly, because a security review finds it either way and finding it here is faster.

  • No single sign-on and no two-factor authentication. Both are on the roadmap and neither ships today.
  • No roles inside an account: every user on an account has the same rights, so a reader can change what colleagues receive. Roles are next on the roadmap.
  • No published third-party audit report, such as SOC 2 or ISO 27001. MBI is a young product and does not hold one.
  • No API into your internal systems, which also means MBI holds no credentials for them.

The documents themselves

This page is a summary written for a reviewer. These are the agreements it summarises, and they are the ones that bind.

Data Processing Agreement Privacy Policy Terms of Service Cookie Policy Ask us something specific