Security at Morasel

Security built into how the platform works

Morasel handles customer conversations and records, so protecting that data is a core part of how we build. This page describes our security practices honestly and at a high level.

Our approach

We follow established security practices and improve them as the platform grows. We describe here what is in place today and what is planned. We do not hold formal certifications, and we do not claim compliance we have not established. If you have a specific security requirement, contact us and we will tell you where we stand.

Practices

What we do to protect your data

  • Tenant isolation

    Each customer's data is scoped to its own tenant. Access is checked on every request so one organization cannot read or change another organization's data.

  • Role-based access control

    Team members are granted access by role. Administrators control who can see and do what, so people only reach the data their job requires.

  • Audit logging

    Security-relevant actions are recorded to an audit log, so sensitive activity can be reviewed and traced when needed.

  • Encryption in transit

    Traffic between your browser or mobile app and Morasel is encrypted using TLS, protecting data as it moves across the network.

  • Encryption at rest

    Where implemented, stored data is encrypted at rest using the encryption features of our cloud infrastructure providers.

  • Secrets management

    Credentials and API keys are kept out of source code and managed through dedicated secrets storage, with access limited to the services that need them.

  • Backups

    Where implemented, we take regular backups of core data so it can be recovered in the event of a failure.

  • Incident handling

    We have a process to investigate suspected security incidents, contain issues, and notify affected customers where appropriate.

  • Data retention controls

    We provide controls to manage how customer data is retained and removed, and we honor opt-in and opt-out preferences across the platform.

  • Secure software development

    Security is considered during development through code review, dependency management, and controlled deployments.

Control matrix

Where each control actually stands

ControlStateCoverageLast verified
Tenant isolationIn placeEvery workspace-owned record reached through the product. The workspace filter is applied by the data layer, not left to each endpoint.2026-09-12
Role-based access controlIn placeThree workspace roles over one shared permission map, enforced in the API and mirrored in the interface. Morasel operator access is a separate map that grants nothing inside your workspace.2026-09-12
Audit loggingIn placeSign-in, team, workspace and Morasel-operator actions, each with the actor, the target and the time.2026-09-12
Encryption in transitIn placeTraffic to the product, and every connection to the database, which refuses unencrypted connections.2026-08-10
Encryption at restIn placeThe managed database and the file storage behind it, using the cloud provider’s own encryption. Stored provider credentials are encrypted again by Morasel before they reach the database.2026-08-10
Secrets managementPartialCredentials are held by reference and encrypted with AES-256-GCM before they are stored. A cloud key-management path is built, but it is not the one running in production.2026-09-12
BackupsPartialDaily backups kept for 14 days, plus point-in-time recovery across 7 days of transaction logs, restored and validated end to end in a drill. Backups sit in the same cloud project as the database; there is no copy outside it.2026-08-10
Incident handlingPartialSuspected incidents are investigated and written up to a fixed shape: what happened, what was exposed, what contained it, what has to be rotated. No customer-notification deadline is published.2026-09-12
Data retentionPartialSix classes of operational data are deleted on a set schedule. Messages, contacts, appointments and media have no retention period set and are kept until the workspace is deleted.2026-08-10
Secure software developmentIn placeEvery change runs lint, a secret scan, type checking, the full test suite and a production build before it can merge, and releases are built by the build service rather than from a workstation.2026-09-12
Independent certificationNot in placeMorasel holds no SOC 2, ISO 27001 or HIPAA certification and does not claim one. Tell us your requirement and we will tell you where we stand.2026-09-12

“Last verified” means someone read the relevant configuration or source on that date and found it to match the row. It is not a third-party audit, a penetration test, or a certification.

Responsible disclosure

If you believe you have found a security vulnerability in Morasel, we want to hear from you. Please email us with the details so we can investigate. We appreciate reports made in good faith and will work with you to understand and resolve valid issues.

Email our security team

  • security@morasel.ai

Security questions

Is Morasel certified for SOC 2, ISO 27001, or HIPAA?

We do not currently hold these certifications and do not claim them. We follow established security practices and can discuss your specific requirements — contact us to learn where we stand.

How is my organization's data kept separate from others?

Data is isolated per tenant, and access is checked on every request so one organization cannot access another organization's data.

Is my data encrypted?

Data is encrypted in transit using TLS. Where implemented, stored data is encrypted at rest using our cloud providers' encryption features.

Who can access data inside my account?

Access is role-based. Your administrators decide who can see and do what, so people only reach the data their role allows.

How do I report a security issue?

Email security@morasel.ai with the details. We review reports made in good faith and will work with you to resolve valid issues.

Have a security question?

Talk to our team about your requirements, or request a demo to see how Morasel handles your data.