Moxu Trust & Security Center

Enterprise Security & Privacy
Built Into Every Layer

Learn how Moxu protects your data, applications, and customer credentials with end-to-end encryption, multi-tenant workspace isolation, continuous vulnerability scanning, and zero AI model training on customer data.

SOC 2 Type II
Independent Annual Audit
AES-256 & TLS 1.3
At Rest & In Transit
Zero AI Training
Private LLM Endpoints
GDPR & ISO 27001
Global Sovereignty Ready
Industry Standards

Compliance & Security Certifications

Moxu complies with leading security standards and regulatory frameworks to ensure your customer applications meet enterprise compliance mandates.

SOC 2 Type II Certified

Audited annually by independent AICPA cyber auditors. Validates operational security, system availability, and data confidentiality across all Moxu cloud environments.

Report Available under NDA

ISO / IEC 27001:2022

Adheres to international Information Security Management System (ISMS) standards covering vulnerability handling, key management, and continuous risk assessment.

Fully Certified

GDPR & CCPA Compliant

Full compliance with EU & California data privacy regulations. Includes Data Processing Addendums (DPA), Standard Contractual Clauses (SCCs), and automated data erasure APIs.

DPA Ready

PCI-DSS Level 1 Partner

Payment card processing is powered by Stripe, a PCI-DSS Level 1 Service Provider. Credit card numbers, CVVs, and raw cardholder data never touch or enter Moxu servers.

Tokenized Checkout

HIPAA Compliance Readiness

For healthcare organizations and medical service providers, Moxu offers dedicated isolated project environments with Business Associate Agreements (BAA).

BAA Available

TLS 1.3 & HSTS Enforced

All web traffic and PWA service worker requests are encrypted using TLS 1.3 with RSA 4096-bit SSL certificates and HTTP Strict Transport Security (HSTS).

A+ Security Grade
Architectural Defense

Four Pillars of Moxu Security

We design our platform with defense-in-depth principles so your business, customer records, and code stay protected 24/7.

1. Multi-Tenant Workspace Isolation & Encryption

Customer data is logically isolated across all database collections and storage buckets. All data at rest is encrypted using AES-256 with Google Cloud Key Management Service (KMS). All network traffic is enforced via TLS 1.3.

  • Strict tenant separation at app & database boundaries
  • Automated daily encrypted database backups
  • Geographic data residency options (US, EU, Canada)

2. Zero AI Training & Strict Data Privacy

Your prompt inputs, application logic, database schemas, and customer interaction logs are never used to train public AI models. We enforce zero-data-retention agreements with AI API providers.

  • Contractual zero-retention SLAs with Google Gemini AI API
  • No customer telemetry used for machine learning models
  • Full GDPR right-to-be-forgotten automated purging

3. Automated Security Scanning & Rule Auditor

Every time you build or update an app on Moxu, our security auditor engine evaluates your Firestore security rules, CORS configurations, rate-limiting limits, and API routes to eliminate misconfigurations before publish.

  • Automatic Firestore security rule validation
  • Real-time dependency vulnerability audits
  • Server-side request permission checks on every route

4. Identity, SAML/SSO & Vault Secret Management

Manage user roles with granular RBAC (Owner, Admin, Editor, Viewer). Secrets such as Stripe API keys and webhooks are stored in encrypted secret vaults and injected strictly on serverless backends.

  • Single Sign-On (SSO) via SAML 2.0 & OIDC for Enterprise
  • Encrypted secret storage with zero client-side leakage
  • Comprehensive audit logs of user login and edit events
Transparency

Authorized Subprocessors Registry

Moxu partners with industry-leading infrastructure and service providers to run our high-availability platform. All subprocessors execute rigorous Data Protection Addendums (DPA).

Subprocessor Purpose Data Location Certifications
G
Google Cloud Platform (GCP / Firebase)
Cloud Infrastructure, Database Storage, Auth & Serverless Compute United States, European Union, Canada SOC 1/2/3, ISO 27001
AI
Google Gemini Enterprise AI
Generative AI Inference & Natural Language Code Synthesis United States (Zero-Retention API Endpoint) Zero-Data-Retention SLA
S
Stripe, Inc.
Subscription Billing, PWA Storefront Payment Processing United States, Global PCI-DSS Level 1
CF
Cloudflare, Inc.
Global CDN Edge Network, DDoS Protection, Web Application Firewall Global Edge Locations SOC 2 Type II, ISO 27001
TW
Twilio / Postmark
Transactional Email Notifications & PWA Web Push SMS Triggers United States, EU SOC 2, GDPR Compliant
Real-time Defense

Automated Guardrails Before Deploy

Unlike traditional web builders where insecure API keys or wide-open database rules get deployed unnoticed, Moxu's internal security bot runs pre-flight automated checks on every publish request.

Firestore Rule Hardening
Verifies read/write auth status so unauthenticated users cannot read private tenant data.
CORS & CSRF Protection
Enforces domain restriction headers to stop cross-site scripting and unauthorized API calls.
moxu-security-auditor.log

[02:56:40] INFO Initiating pre-publish security audit for project 'moxu-storefront'...

[02:56:41] INFO Auditing Firestore rules...

✓ PASS: Collection 'orders' restricts write access to request.auth.uid

✓ PASS: Collection 'customers' prevents public read queries

[02:56:42] INFO Checking secret environment variables...

✓ PASS: Stripe Secret Key encrypted with Google Cloud KMS (AES-256)

✓ PASS: No secret keys leaked in frontend bundle assets

[02:56:43] INFO Auditing AI model privacy boundary...

✓ PASS: Gemini API request header sets zero-data-retention flag

🔒 AUDIT COMPLETE: 0 Vulnerabilities Found. Safe to deploy.

Clear Answers

Frequently Asked Security Questions

Everything you need to know about how we manage your data and privacy.

Customer data is hosted in high-availability Google Cloud Data Centers (Firebase Cloud Infrastructure) located in supported regions including North America (US-East/Canada), Europe (Frankfurt), and Asia-Pacific. Data residency can be configured for enterprise clients to comply with local data protection mandates.
No, never. Customer prompts, web app layout configurations, source code, and database records are explicitly excluded from machine learning model training. All integrations with AI providers use enterprise zero-data-retention endpoints bound by legally binding data protection agreements.
No. Moxu operates in an isolated environment and does not require direct access to your internal production infrastructure or private GitHub repositories. When exporting code or syncing changes, integrations operate strictly via OAuth permission tokens that you can revoke at any time.
Secrets are encrypted at rest using AES-256 keys managed by Cloud KMS. API credentials are encrypted before storage and are injected exclusively into isolated server-side cloud functions. They are never exposed in frontend browser bundles or client-side Javascript.
Yes. Moxu complies with GDPR regulations, providing full data portability, automated deletion mechanisms, and standard Data Processing Addendums (DPA). Our infrastructure undergoes annual third-party SOC 2 Type II audits. Enterprise customers can request our SOC 2 report under NDA.
All database collections undergo continuous multi-region automated replication. In the event of a regional cloud outage, failover mechanisms switch to redundant database clusters with a Recovery Point Objective (RPO) of < 1 minute and a Recovery Time Objective (RTO) of < 15 minutes.
Moxu engages CREST-accredited third-party cybersecurity firms to perform comprehensive grey-box and black-box penetration tests twice a year. Executive summaries of our latest pen test report are available for Enterprise accounts upon request.

Found a vulnerability? Report it responsibly.

We work closely with the security research community. If you suspect a potential security issue on Moxu, please contact our dedicated security team.