Security

Security claims should be specific and verifiable

This page describes our current operating approach. It does not claim that Mopshy AI holds SOC 2, ISO 27001, HIPAA, or other third-party certification.

Current approach

Controls and design principles we use

Data minimization

We design workflows to collect and retain only the data required for the agreed business process.

Scoped access

Access to client systems is requested for a defined delivery need and should use the minimum permissions practical for that integration.

Secrets handling

API keys and other credentials belong in managed environment or secret stores, not public client-side configuration or source content.

Managed hosting

Mopshy's website currently uses Vercel for application hosting and Supabase for authentication and data services. Client architectures are selected per engagement.

Encrypted transport

Public production traffic is served over HTTPS through managed hosting. Additional encryption and key-management requirements are defined per client architecture.

Client ownership

Where practical, production systems are deployed into client-owned accounts with source-controlled handoff and documented operating responsibility.

Security requirements vary by client, data class, and deployment model. For regulated or procurement-led engagements, required controls, vendors, retention, access, incident obligations, and evidence should be agreed in writing before production access is granted.

30-minute working session

Find the highest-ROI automation in your business

Bring one workflow that is slow, repetitive, or leaking opportunities. We will map the bottleneck, the systems involved, and whether automation is actually worth implementing.

Book an AI systems assessment

No obligation. If automation is not the right answer, we will say so.