Learn how Moxu protects your data, applications, and customer credentials with end-to-end encryption, multi-tenant workspace isolation, continuous vulnerability scanning, and zero AI model training on customer data.
Moxu complies with leading security standards and regulatory frameworks to ensure your customer applications meet enterprise compliance mandates.
Audited annually by independent AICPA cyber auditors. Validates operational security, system availability, and data confidentiality across all Moxu cloud environments.
Report Available under NDAAdheres to international Information Security Management System (ISMS) standards covering vulnerability handling, key management, and continuous risk assessment.
Fully CertifiedFull compliance with EU & California data privacy regulations. Includes Data Processing Addendums (DPA), Standard Contractual Clauses (SCCs), and automated data erasure APIs.
DPA ReadyPayment card processing is powered by Stripe, a PCI-DSS Level 1 Service Provider. Credit card numbers, CVVs, and raw cardholder data never touch or enter Moxu servers.
Tokenized CheckoutFor healthcare organizations and medical service providers, Moxu offers dedicated isolated project environments with Business Associate Agreements (BAA).
BAA AvailableAll web traffic and PWA service worker requests are encrypted using TLS 1.3 with RSA 4096-bit SSL certificates and HTTP Strict Transport Security (HSTS).
A+ Security GradeWe design our platform with defense-in-depth principles so your business, customer records, and code stay protected 24/7.
Customer data is logically isolated across all database collections and storage buckets. All data at rest is encrypted using AES-256 with Google Cloud Key Management Service (KMS). All network traffic is enforced via TLS 1.3.
Your prompt inputs, application logic, database schemas, and customer interaction logs are never used to train public AI models. We enforce zero-data-retention agreements with AI API providers.
Every time you build or update an app on Moxu, our security auditor engine evaluates your Firestore security rules, CORS configurations, rate-limiting limits, and API routes to eliminate misconfigurations before publish.
Manage user roles with granular RBAC (Owner, Admin, Editor, Viewer). Secrets such as Stripe API keys and webhooks are stored in encrypted secret vaults and injected strictly on serverless backends.
Moxu partners with industry-leading infrastructure and service providers to run our high-availability platform. All subprocessors execute rigorous Data Protection Addendums (DPA).
| Subprocessor | Purpose | Data Location | Certifications |
|---|---|---|---|
|
G
Google Cloud Platform (GCP / Firebase)
|
Cloud Infrastructure, Database Storage, Auth & Serverless Compute | United States, European Union, Canada | SOC 1/2/3, ISO 27001 |
|
AI
Google Gemini Enterprise AI
|
Generative AI Inference & Natural Language Code Synthesis | United States (Zero-Retention API Endpoint) | Zero-Data-Retention SLA |
|
S
Stripe, Inc.
|
Subscription Billing, PWA Storefront Payment Processing | United States, Global | PCI-DSS Level 1 |
|
CF
Cloudflare, Inc.
|
Global CDN Edge Network, DDoS Protection, Web Application Firewall | Global Edge Locations | SOC 2 Type II, ISO 27001 |
|
TW
Twilio / Postmark
|
Transactional Email Notifications & PWA Web Push SMS Triggers | United States, EU | SOC 2, GDPR Compliant |
Unlike traditional web builders where insecure API keys or wide-open database rules get deployed unnoticed, Moxu's internal security bot runs pre-flight automated checks on every publish request.
[02:56:40] INFO Initiating pre-publish security audit for project 'moxu-storefront'...
[02:56:41] INFO Auditing Firestore rules...
✓ PASS: Collection 'orders' restricts write access to request.auth.uid
✓ PASS: Collection 'customers' prevents public read queries
[02:56:42] INFO Checking secret environment variables...
✓ PASS: Stripe Secret Key encrypted with Google Cloud KMS (AES-256)
✓ PASS: No secret keys leaked in frontend bundle assets
[02:56:43] INFO Auditing AI model privacy boundary...
✓ PASS: Gemini API request header sets zero-data-retention flag
🔒 AUDIT COMPLETE: 0 Vulnerabilities Found. Safe to deploy.
Everything you need to know about how we manage your data and privacy.
We work closely with the security research community. If you suspect a potential security issue on Moxu, please contact our dedicated security team.