Data Security, Processing & Storage
Last updated on 12 July 2026Your data remains yours. MangoMap keeps customer data private by default and uses it only as needed to provide the Service. We take security seriously because map data can include sensitive operational, commercial, or personal information.
This page describes the controls we have in place. A fuller Security and Privacy Overview, written for security reviews and vendor due diligence, is available on request; see Security reviews and due diligence below.
Certifications and Compliance
All customer data is stored and processed on Amazon Web Services, which holds SOC 1, SOC 2 Type II and SOC 3 reports, and ISO/IEC 27001, 27017, 27018 and 27701 certification, among others.
Our billing provider, Recurly, operates a PCI DSS Level 1 audited environment. MangoMap does not store or process payment card data.
We align our own practices with the EU and UK GDPR, the Australian Privacy Principles, Canada's PIPEDA, California's CCPA/CPRA, New Zealand's Privacy Act 2020, and India's Digital Personal Data Protection Act 2023. Our Privacy Policy sets out how that works in practice, including the sub-processors we rely on and how international transfers are handled.
Where Your Data Is Stored
Customer data is stored and processed in the Amazon Web Services US East region (us-east-1, Northern Virginia). This applies to all our primary data stores. Backups are replicated across multiple Availability Zones within that region.
MangoMap operates a single-region deployment. Regional data residency in other jurisdictions (for example an EU or Asia-Pacific region) is not currently available, and all customers are hosted in the same region. Content delivery network edge locations may cache static map assets globally for performance, which is normal for any CDN-fronted service.
Encryption
At rest. All customer data is encrypted at rest. Our relational database (Amazon Aurora PostgreSQL, including PostGIS spatial data) is encrypted using AWS Key Management Service. Application data in DynamoDB and file storage in S3 (which holds your uploads and generated map tiles) are encrypted with AES-256. Automated backups are held in an encrypted backup vault.
In transit. Connections to the MangoMap application and API require TLS 1.2 or higher.
Infrastructure and Physical Security
MangoMap does not operate its own data centres. Physical and environmental security is provided by Amazon Web Services, our infrastructure provider, and we inherit those controls.
More on AWS security can be found here and here.
Network Isolation
Application services run within a private network. Our databases are not reachable from the internet.
Authentication
Authentication and credential storage are handled by Amazon Cognito. Account passwords are never stored by MangoMap.
Access Control and Tenant Isolation
Each customer's data is logically isolated by account, enforced on every authenticated request. Access to an individual map or dataset is granted only if the requesting user created it, is the account owner, belongs to a user group the resource has been shared with, or the resource has been published.
Account roles
An account can have multiple users. The account owner invites and removes users, and each user holds one of four roles:
| Role | What it allows |
|---|---|
| Owner | Full control: account settings, billing, inviting and removing users, changing roles, managing user groups and group membership, and access to every resource in the account regardless of how it is shared. |
| Admin | Everything an Editor can do, plus creating maps and datasets, importing and deleting data, editing maps, and sharing resources they own by assigning existing groups to them. Admins cannot create, edit or delete user groups, or change group membership. |
| Editor | Everything a Viewer can do, plus editing datasets they created or have been granted group-edit access to, and editing dataset features on maps. Editors cannot create maps or datasets, and cannot edit maps. |
| Viewer | View the maps and datasets they have been given access to. No create or edit rights. |
Resource-level access
Beyond account-wide roles, access can be scoped to individual maps and datasets through user groups, so specific users can be restricted to specific resources rather than the whole account. User groups are scoped to a single account and contain only that account's own users, so group-based sharing never extends access to anyone outside your organisation. Per-resource access control is available on the Enterprise and Agency plans.
Sharing and publication
New maps and datasets are private by default.
Internal access always applies. A map can always be opened by its owner and by signed-in users of your account who have been granted access to it through a user group. This does not depend on any publishing setting, and it is the only form of access that ties a map to individually authenticated people. If a map is not published to the web, internal access is the only way to reach it.
Publishing to the web is a separate, explicit choice. A map is not reachable outside your account until its creator publishes it to the web. When they do, they choose how it is exposed:
- Public: anyone can open the map, and it becomes eligible to appear in the public portal and be indexed by search engines. Search indexing is off by default.
- Link-only: reachable only through a secret link containing a random, unguessable identifier in place of the map's ID. The map is neither listed nor indexed, and the link can be regenerated at any time to invalidate the previous one. A link-only map is unguessable, but it is not individually access-controlled, so it is a sharing convenience rather than a private-access mechanism.
- Password: the map is reachable by URL, but a viewer must enter the map's password to open it.
Password-protected maps are a deliberately lightweight sharing convenience: the password is set by, and visible to, the map's owner. This mode is not intended to meet high-security access requirements. If you need to restrict access strictly, do not publish the map to the web. Use internal access and user groups instead, which tie access to individually authenticated users within your account rather than to a single shared password.
Datasets use a simpler public on/off setting, with no link-only or password mode.
Data access and downloads
There is no separate "download" permission: anyone who can view a dataset can export it in full. An export contains every feature and every attribute in that dataset, not just the parts visible on screen. It is not a filtered or sampled extract.
Two consequences follow:
- Granting view access to a dataset grants the ability to take a full copy of it. A Viewer, or a user given group view-only access, can download the whole dataset. If some attributes in a dataset are sensitive, the control that matters is whether that data is in the dataset at all: remove it before upload, or keep it in a separate dataset that is shared with fewer people.
- A dataset set to public can be downloaded in full by anyone on the internet, including visitors who are not signed in.
Decide what to share at the level of the dataset, and treat any dataset you publish as published.
Backups and Disaster Recovery
Automated database backups run daily and are retained for 14 days, written to an encrypted backup vault and stored across multiple Availability Zones. We maintain a documented disaster recovery process and exercise it periodically.
Secure Development and Testing
- Every change is peer-reviewed before it can be merged, and automated checks must pass.
- Continuous delivery means security patches reach production quickly.
- We run automated security scanning against every release, covering our code, our dependencies, our infrastructure configuration and our running application.
Personnel and Internal Access
- New hires undergo background checks.
- All employees complete security training and formally acknowledge MangoMap's security policies.
- Access to resources is granted on a least-privilege basis, and access to sensitive data is logged and monitored.
- Administrative access to our cloud and source-control consoles requires hardware-based two-factor authentication.
- Developers work only with anonymised data. Production customer data is not used in development.
- Onboarding and offboarding procedures, including access provisioning and revocation, are documented.
Employee Access to Your Data
No MangoMap employee accesses your User Data unless it is required to resolve a support issue, and then only with the consent of an authorised Account holder.
Our support staff may log into your account to access settings related to your support issue. When working on a support issue, we do our best to respect your privacy as much as practicable, accessing only the files and settings needed to resolve it.
Data Ownership and Usage
User Data is exclusively owned by you. MangoMap Limited will use this data only as necessary to provide the Service, and will not share it with third parties except as described in our Privacy Policy. Examples of data usage include account management, service improvement, and customer support.
We use third-party vendors and hosting partners to provide the hardware, software, networking, storage and related technology required to run the Service. Although we own the code, databases and all rights to the Service, you retain all rights to your User Data.
Health Data and HIPAA
MangoMap is not a healthcare-focused product and does not hold itself out as HIPAA-compliant. While the majority of our technical and physical safeguards meet or exceed the relevant requirements, we have not sought to actively comply with the U.S. Health Insurance Portability and Accountability Act of 1996, and we do not recommend that covered entities use MangoMap to process or store electronic protected health information (ePHI).
Where data uploaded to MangoMap has been de-identified in accordance with the HIPAA Privacy Rule, that data is not considered ePHI and MangoMap is not a business associate, so there are no HIPAA restrictions on using MangoMap to analyse such health data.
Vulnerability Disclosure
MangoMap welcomes the responsible disclosure of security issues, and we value the work of security researchers.
If you discover a security vulnerability in MangoMap, please report it to security@mangomap.com. We acknowledge legitimate, good-faith reports within 48 hours and provide status updates as we investigate.
Security Incidents and Breach Notification
In the event of a personal data breach, we will:
- Investigate the scope and impact promptly on becoming aware of the incident, invoking our cyber-incident response plan
- Notify the affected customer's account administrator within 6 hours of confirming a breach, by email, with updates as the situation is assessed
- Notify the relevant regulators within 72 hours where required, in accordance with the laws applicable to you: the UK Information Commissioner's Office, EU supervisory authorities, and the Office of the Australian Information Commissioner, among others
- Provide affected parties with a full incident report covering the data involved, the mitigation steps taken, and recommended actions
Data Processing Agreement
A Data Processing Agreement is available to customers on request. It covers our obligations as your processor, our sub-processors and notification of changes to them, international transfers, breach notification, and the return or deletion of your data on termination.
Contact support@mangomap.com to request one.
Security Reviews and Due Diligence
This page is a summary. We maintain a detailed Security and Privacy Overview for customers and prospects conducting vendor due diligence, security reviews or audit responses. It describes each control in more depth and lists our sub-processors in full.
To request it, or to send us a security questionnaire, contact security@mangomap.com.
Changes to This Policy
We review this page, and our wider information security programme, at least annually, and update them as necessary in response to new or evolving risks, changes to our data processing practices, and the availability of improved controls. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address on your account, or by placing a prominent notice on our site.
How can you contact us about this notice?
If you have any questions or concerns about this security information please contact us.
Security reports and questions: security@mangomap.com
General queries: support@mangomap.com
1 Victoria Street
Bristol, BS1 6AA
United Kingdom