What Moosewave protects today.
See the controls in place, where website data is stored, who may access it, and which audits and certifications Moosewave does not have.
What this page covers
The website and the product are separate.
The public website collects update, feedback, and demo-survey records. The product workspace has its own account protections. We describe each without treating one as proof for the other.
Public website
Forms and site services
Website records are stored in AWS in Stockholm. Email delivery and the business mailbox use AWS in Ireland. Authorised team members may access records from India.
Product workspace
Account data and access
Database rules separate one account from another. Customer-data locations and product terms will be documented before public signup opens.
These controls are not a certification, audit report, or uptime promise.
Current controls
How protection works in practice.
Open any item for the implementation detail and its current limit. These are product controls, not third-party assurances.
Account separationDatabase rules limit each request to the account making it.
Each product record includes an account identifier. Row-level security policies in the database use that identifier, rather than relying only on application code.
A request with no account context returns no records. This reduces the risk that a missing filter in application code exposes another account's data.
EncryptionConnections use TLS, and stored data uses infrastructure-level encryption.
Data is encrypted in transit using TLS and at rest using the encryption provided by our infrastructure services.
Credentials and API keys are stored hashed or encrypted rather than as plain text. Technical reviewers can ask about algorithms, key management, and key access.
Access to production systemsOnly engineers who need access receive it, with multi-factor authentication required.
Access uses the cloud provider's identity system and requires multi-factor authentication. Infrastructure changes are defined as code so the change history can be reviewed.
The engineers building Moosewave also operate it. There is no separate security operations team today.
Vulnerability handlingBuilds scan dependencies for known issues, and the team reviews relevant security notices.
Dependencies are scanned during the build, and we track security notices for the languages and services Moosewave uses.
Security reports are accepted at info@moosewave.com. Moosewave does not currently run a paid bug bounty programme.
Public website
Services that handle website data.
This list covers the public website. Product-specific data terms and a provider list will be published before customer data is accepted.
| Service | Why it is used | Location or limit |
|---|---|---|
| Amazon Web Services | Website hosting, forms, database, queues, email delivery, and business mailbox | Form records: Stockholm. Email delivery and mailbox: Ireland. |
| PostHog | Optional site analytics after consent | EU project when configured. No advertising or session replay. |
| Sentry | Optional browser error reports after consent | EU project when configured. Sensitive fields are removed before sending. |
No product data-processing agreement is represented as active for a website visitor.
Not currently in place
Independent assurance and current status.
We list these gaps directly so current controls are not mistaken for independent verification.
- SOC 2 Type II
- Moosewave has not completed a SOC 2 audit or certification
- ISO 27001
- Not certified
- HIPAA
- Moosewave does not support HIPAA-regulated workloads; do not send protected health information
- Third-party penetration test
- Not commissioned yet
- Paid bug bounty
- Not currently offered
- Published uptime SLA
- Not currently offered
Security contact
Report an issue or ask a question.
We will acknowledge reports. Please allow a reasonable time to investigate before publishing details.
