Trust Center

Security Overview

A concise summary of the technical and organizational security measures inMOLA operates today, plus the certification roadmap enterprise procurement teams typically ask about.

Last updated: August 21, 2026

Download the Security Overview

Same content as this page, in a PDF you can attach to your vendor file.

Request PDF →

1. Company & scope

inMOLA Teknoloji Yazılım Hizmetleri A.Ş. operates the inMOLA marketing intelligence platform. All information below applies to the SaaS services provided at inmola.com and app.inmola.com.

2. Infrastructure

  • Production hosted on managed Linux servers with hardened OS baseline
  • All customer traffic served over HTTPS (TLS 1.2+); HSTS enforced with preload
  • Isolated production environment; no shared credentials between environments
  • Database engine: PostgreSQL and SQLite (per service tier), with encrypted backups
  • Application layer: Next.js on Node.js; Payload CMS for content operations

3. Access controls

  • Role-based access control (RBAC) with least-privilege defaults
  • Multi-factor authentication (2FA/TOTP) required for administrative access
  • Single-session enforcement on administrative accounts (concurrent logins blocked)
  • Brute-force protection: 5 failed attempts → 15-minute lockout
  • Complete audit trail of administrative actions
  • Access review at onboarding, role change, and offboarding

4. Data protection

  • Encryption in transit: TLS 1.2+ for all endpoints
  • Encryption at rest: applied to sensitive fields (credentials, tokens, PII markers)
  • Payment data is handled entirely by iyzico (PCI-DSS Level 1) — inMOLA never stores full card numbers
  • Backups: daily encrypted backups with retention aligned to data class
  • Data minimization: fields not required for the service are not collected

5. AI processing — customer data is not used for model training

Customer data transmitted to third-party AI service providers (OpenAI, Anthropic, Google Gemini, Perplexity) is not used to train models under those providers' standard API terms. inMOLA does not use customer data to train any AI models, does not share customer data with third parties for training, and does not retain customer data for fine-tuning purposes.

AI provider responses are returned to the customer within the intelligence module and retained only per documented service retention policy.

6. Monitoring & incident response

  • Continuous application and infrastructure monitoring with alerting
  • Structured incident response procedure — triage, containment, recovery, post-mortem
  • Documented breach notification workflow that meets the GDPR 72-hour reporting requirement
  • Regular security review of dependencies via automated tooling

7. Sub-processors

Full list is maintained on the GDPR & KVKK page and includes:

  • iyzico — payment processing (PCI-DSS Level 1)
  • Brevo — transactional and marketing email (EU)
  • Google (Analytics 4) — anonymized usage analytics (consent-gated)
  • OpenAI, Anthropic, Google Gemini, Perplexity — AI processing for specific modules

Sub-processor changes are communicated to enterprise customers by email.

8. People & training

  • All personnel signed to confidentiality obligations at onboarding
  • Security awareness training at onboarding and annually
  • Development team follows secure coding review practices for every merged change

9. Independent certifications — roadmap

inMOLA does not currently hold independent information security certifications. Our compliance roadmap targets:

  • ISO/IEC 27001 — targeted for completion within 2027
  • SOC 2 Type II — targeted for completion within 2027 (aligned with ISO 27001 work)
  • ISO 9001 — evaluated in parallel; commitment dependent on customer demand signal

The administrative and technical controls that form the base of ISO 27001 are applied today, and internal gap analyses are conducted on a rolling basis.

10. Contact security

To report a security concern, request a technical questionnaire, or engage on a security review:

Also see: Security · GDPR & KVKK · DPA