Skip to content

Trust center

Security at Mantle

How Mantle protects access to connected accounting workflows and how to report a security concern.

Effective and last updated: September 28, 2026

Access boundaries

Mantle ties requests to authenticated accounts, selected workspaces, business connections, and explicit permissions. Workspace owners control subuser access. Sensitive Manager connection secrets are not placed in public extension URLs.

Verified accounting operations

Write operations are prepared as drafts and require explicit confirmation unless a user has deliberately enabled a described automation. Manager references are validated against the selected business, and completed writes are verified before Mantle reports success.

Data protection

Mantle uses encrypted transport for deployed services and protects stored credentials securely. Production secrets should be supplied through the deployment platform and must never be committed to source control or shared in support communities.

Operational safeguards

We use scoped permissions, validation, audit records, usage controls, and failure-safe behavior around AI, OCR, and connected-provider operations. No system is risk-free, and customers should maintain suitable accounting backups and periodically review user access.

Responsible disclosure

If you believe you found a vulnerability, email hello@mantle.io with a clear description and reproduction steps. Do not access other users’ data, disrupt production, use social engineering, or publicly disclose the issue before we have had a reasonable opportunity to investigate.