Skip to content
Moosewave
Demo
Security · reviewed 5 September 2026

What Moosewave protects today.

See the controls in place, where website data is stored, who may access it, and which audits and certifications Moosewave does not have.

What this page covers

The website and the product are separate.

The public website collects update, feedback, and demo-survey records. The product workspace has its own account protections. We describe each without treating one as proof for the other.

Public website

Forms and site services

Website records are stored in AWS in Stockholm. Email delivery and the business mailbox use AWS in Ireland. Authorised team members may access records from India.

Product workspace

Account data and access

Database rules separate one account from another. Customer-data locations and product terms will be documented before public signup opens.

These controls are not a certification, audit report, or uptime promise.

Current controls

How protection works in practice.

Open any item for the implementation detail and its current limit. These are product controls, not third-party assurances.

Account separationDatabase rules limit each request to the account making it.

Each product record includes an account identifier. Row-level security policies in the database use that identifier, rather than relying only on application code.

A request with no account context returns no records. This reduces the risk that a missing filter in application code exposes another account's data.

EncryptionConnections use TLS, and stored data uses infrastructure-level encryption.

Data is encrypted in transit using TLS and at rest using the encryption provided by our infrastructure services.

Credentials and API keys are stored hashed or encrypted rather than as plain text. Technical reviewers can ask about algorithms, key management, and key access.

Access to production systemsOnly engineers who need access receive it, with multi-factor authentication required.

Access uses the cloud provider's identity system and requires multi-factor authentication. Infrastructure changes are defined as code so the change history can be reviewed.

The engineers building Moosewave also operate it. There is no separate security operations team today.

Vulnerability handlingBuilds scan dependencies for known issues, and the team reviews relevant security notices.

Dependencies are scanned during the build, and we track security notices for the languages and services Moosewave uses.

Security reports are accepted at info@moosewave.com. Moosewave does not currently run a paid bug bounty programme.

Public website

Services that handle website data.

This list covers the public website. Product-specific data terms and a provider list will be published before customer data is accepted.

Public website service providers, purposes, and locations
ServiceWhy it is usedLocation or limit
Amazon Web ServicesWebsite hosting, forms, database, queues, email delivery, and business mailboxForm records: Stockholm. Email delivery and mailbox: Ireland.
PostHogOptional site analytics after consentEU project when configured. No advertising or session replay.
SentryOptional browser error reports after consentEU project when configured. Sensitive fields are removed before sending.

No product data-processing agreement is represented as active for a website visitor.

Not currently in place

Independent assurance and current status.

We list these gaps directly so current controls are not mistaken for independent verification.

SOC 2 Type II
Moosewave has not completed a SOC 2 audit or certification
ISO 27001
Not certified
HIPAA
Moosewave does not support HIPAA-regulated workloads; do not send protected health information
Third-party penetration test
Not commissioned yet
Paid bug bounty
Not currently offered
Published uptime SLA
Not currently offered

Security contact

Report an issue or ask a question.

We will acknowledge reports. Please allow a reasonable time to investigate before publishing details.