Compliance

Built to pass an audit. Honest that it hasn't had one yet.

MOQOM's controls are designed to align with SOC 2 and ISO 27001, and machines enforce and evidence as many of them as possible. Nothing is certified today, and we won't say otherwise until an independent auditor has.

SOC 2

Aligning · audit planned
  • Controls are mapped to the Trust Services Criteria for security, availability, confidentiality and processing integrity.
  • A Type I audit comes first, then Type II. No audit has happened yet, so we don't hold a report.

ISO/IEC 27001:2022

Aligning · audit planned
  • Every Annex A control has an owner, a status and a named source of evidence, with a Statement of Applicability.
  • Certification follows the SOC 2 audit.

GDPR and UK GDPR

In place
  • Records of processing are kept, and a personal-data breach is reported to the supervisory authority within 72 hours.
  • Media is relayed, not stored. Personal data past its retention period is deleted or anonymised.
  • A data processing agreement with Standard Contractual Clauses is in legal review. Ask us for the draft.

CCPA / CPRA

In place
  • We don't sell or share personal information.
  • Requests to access or delete data are answered within 45 days.

PCI DSS

In place
  • Card details are entered on Stripe's hosted checkout and never reach MOQOM's servers, logs or database. Stripe is a PCI DSS Level 1 service provider.
  • That puts MOQOM in Self-Assessment Questionnaire A scope. The annual SAQ A and attestation are being prepared.

Child safety, takedowns and accessibility

Planned
  • COPPA, DMCA notice and takedown, the EU Digital Services Act and accessibility each have a written plan.
  • Moderation actions are audit-logged. Actions a model took name the model, so appeals have a record.
Your account

Turnkey to set up. Walled off from everyone else.

Sign up, add credit through Stripe’s hosted checkout, and get an API key for your account. From then on, every request is checked against your tenant.

  • Keys scoped to you

    Your API key reads and changes only your tenant. It’s shown once, stored only as a hash and revocable instantly.

  • Every request checked

    Every token names your tenant, and relays check it against every namespace a request touches. Another tenant’s rooms simply return “not found”.

  • Cards never touch us

    Payment details go straight to Stripe. MOQOM keeps only Stripe’s reference IDs and your prepaid balance.

Isolation is enforced in software on shared infrastructure. Dedicated per-tenant infrastructure isn’t offered yet.

Privacy

Your users are managed by you, not tracked by us.

  • Analytics that don’t follow people

    Site analytics are anonymous visit counts: no Google signals, no ad storage, no sign-in IDs, and opt-in first in the EU, UK and Switzerland. Usage is metered as role, quality tier, seconds and bytes, never as a profile of a person. The SDKs contain no advertising IDs or ad keys. They’re banned from MOQOM’s code, and if your app uses them, that’s your choice to add.

  • Addresses fade

    Participant IP addresses are blanked 30 days after they’re last seen. Media is never stored, and safety signals are pseudonymised, with no addresses or media in them.

  • Users and live logs, built in

    The Go and Rust SDKs manage participants, roles, grants, bans and mutes, and stream every join, leave and moderation action live. The Swift SDK has structured logging built in.

Controls

In place today

Each of these operates in production or in shipped code now. A nightly automated check of the cloud project, which writes a dated report to locked storage, is being switched on next.

Encryption in transitTLS 1.3 on every QUIC connection, mutual TLS between relays and the control plane, encrypted-only database connections
Encryption at restAES-256 on all stored data, with SFrame end-to-end media encryption available per room
Media retentionRelayed, never recorded unless you attach a recorder, and every recorder is disclosed to the room
NetworkPrivate cluster nodes and a database on a private IP only, with no public address
CredentialsNo downloadable service account keys. API keys are stored hashed, shown once and revocable
Tenant isolationA key reads only its own tenant's data, and every token is checked against every namespace it touches
Audit trailGoogle Cloud admin activity logs, kept for 400 days and locked against tampering
Billing recordsAn append-only ledger, kept for 7 years and never edited
InfrastructureEvery environment is defined in Terraform and can be rebuilt from it. Deployed images are pinned by digest
Subprocessors

Who processes your data

Customers get 30 days’ notice before a new subprocessor handles their data.

CompanyPurposeLocation
Google CloudHosting: compute, database, storage, loggingUnited States (us-west1, us-west2)
StripePayments, checkout and invoicesUnited States
GitHubSource code and CI. No customer personal dataUnited States
Hover (Tucows)Company email, domains and DNSCanada and United States

Questionnaires, DPAs and data requests

For a security questionnaire, the draft DPA, or a request to access or delete your data, email hello@moqom.cloud. Security issues go to security@moqom.cloud. See also Security and the privacy notice.