Security built into how the platform works
Morasel handles customer conversations and records, so protecting that data is a core part of how we build. This page describes our security practices honestly and at a high level.
Our approach
We follow established security practices and improve them as the platform grows. We describe here what is in place today and what is planned. We do not hold formal certifications, and we do not claim compliance we have not established. If you have a specific security requirement, contact us and we will tell you where we stand.
What we do to protect your data
Tenant isolation
Each customer's data is scoped to its own tenant. Access is checked on every request so one organization cannot read or change another organization's data.
Role-based access control
Team members are granted access by role. Administrators control who can see and do what, so people only reach the data their job requires.
Audit logging
Security-relevant actions are recorded to an audit log, so sensitive activity can be reviewed and traced when needed.
Encryption in transit
Traffic between your browser or mobile app and Morasel is encrypted using TLS, protecting data as it moves across the network.
Encryption at rest
Where implemented, stored data is encrypted at rest using the encryption features of our cloud infrastructure providers.
Secrets management
Credentials and API keys are kept out of source code and managed through dedicated secrets storage, with access limited to the services that need them.
Backups
Where implemented, we take regular backups of core data so it can be recovered in the event of a failure.
Incident handling
We have a process to investigate suspected security incidents, contain issues, and notify affected customers where appropriate.
Data retention controls
We provide controls to manage how customer data is retained and removed, and we honor opt-in and opt-out preferences across the platform.
Secure software development
Security is considered during development through code review, dependency management, and controlled deployments.
Responsible disclosure
If you believe you have found a security vulnerability in Morasel, we want to hear from you. Please email us with the details so we can investigate. We appreciate reports made in good faith and will work with you to understand and resolve valid issues.
- security@morasel.ai
Security questions
Is Morasel certified for SOC 2, ISO 27001, or HIPAA?
We do not currently hold these certifications and do not claim them. We follow established security practices and can discuss your specific requirements — contact us to learn where we stand.
How is my organization's data kept separate from others?
Data is isolated per tenant, and access is checked on every request so one organization cannot access another organization's data.
Is my data encrypted?
Data is encrypted in transit using TLS. Where implemented, stored data is encrypted at rest using our cloud providers' encryption features.
Who can access data inside my account?
Access is role-based. Your administrators decide who can see and do what, so people only reach the data their role allows.
How do I report a security issue?
Email security@morasel.ai with the details. We review reports made in good faith and will work with you to resolve valid issues.
Have a security question?
Talk to our team about your requirements, or request a demo to see how Morasel handles your data.