Skip to main content

Our Security Commitment

Moss is built with security as a foundational principle. We understand that our platform processes sensitive user interactions and business data, and we take that responsibility seriously. This documentation outlines the security measures implemented in Moss to protect your data and your users.

Security Architecture

Defense in Depth

Moss employs multiple layers of security controls:

Multi-Tenancy Isolation

Every Moss application is isolated at the organization level:
  • Database Isolation - All queries filter by organization ID
  • API Isolation - JWT tokens scope access to specific organizations
  • Data Isolation - Users cannot access data from other organizations

Compliance Commitments

Moss is actively pursuing industry-standard security certifications:

In Progress

Current Compliance

  • GDPR - Data deletion service, audit logging, user consent mechanisms
  • HTTPS Everywhere - All data transmitted over TLS 1.2+
  • Secure Credential Storage - Cryptographic hashing for all secrets

Security Features Overview

Authentication

JWT tokens, API keys, and multi-factor authentication

Data Protection

Encryption, input validation, and secure storage

Audit Logging

Comprehensive audit trails and compliance reporting

Compliance

GDPR, SOC 2, ISO 27001, and EU AI Act

Responsible Disclosure

If you discover a security vulnerability in Moss, please report it responsibly. Contact our security team through the Dashboard or email security@viamoss.ai. We appreciate your help in keeping Moss secure for everyone.