Back to Directory
HIGH RISK

Mendix

EU/Global (customer-cloud choice) ·Social Housing
OVERALL RISK SCORE 72/100
SOC 2Compliant
GDPRCompliant
Trains on User DataNo
Enterprise TierAvailable
Data RetentionZero Retention
Data ResidencyEU/Global (customer-cloud choice)

Risk Summary

Mendix (Siemens-owned) is increasingly used by UK housing associations to build custom low-code applications that extend core housing management systems. The risk profile is unique: Mendix itself is SOC 2 and GDPR compliant with zero-retention options, but the low-code applications built on top of it are the responsibility of individual housing associations. Many of these citizen-developed apps process tenant data without formal governance reviews, creating shadow AI risk similar to spreadsheet proliferation in finance departments.

Technical Briefing

Housing associations use Mendix to build custom tenant portals, repair booking apps, and arrears calculators. These applications often access core housing system APIs with broad data scopes. Without central governance, individual teams may create apps that combine tenant data in ways not covered by existing DPIAs. Mendix Enterprise supports zero-retention and private cloud deployment, but the governance gap is in the applications built on the platform, not the platform itself.

VULNERABLE TOOL DETECTED

Mendix carries a high enterprise risk profile. Our recommended secure alternative is Mendix Enterprise (centralised platform governance, mandatory DPIA for every deployed app, API scope restrictions, quarterly citizen-developer audit).

Run an automated statement check →