SOC 2
Aligning · audit planned- Controls are mapped to the Trust Services Criteria for security, availability, confidentiality and processing integrity.
- A Type I audit comes first, then Type II. No audit has happened yet, so we don't hold a report.
MOQOM's controls are designed to align with SOC 2 and ISO 27001, and machines enforce and evidence as many of them as possible. Nothing is certified today, and we won't say otherwise until an independent auditor has.
Sign up, add credit through Stripe’s hosted checkout, and get an API key for your account. From then on, every request is checked against your tenant.
Your API key reads and changes only your tenant. It’s shown once, stored only as a hash and revocable instantly.
Every token names your tenant, and relays check it against every namespace a request touches. Another tenant’s rooms simply return “not found”.
Payment details go straight to Stripe. MOQOM keeps only Stripe’s reference IDs and your prepaid balance.
Isolation is enforced in software on shared infrastructure. Dedicated per-tenant infrastructure isn’t offered yet.
Site analytics are anonymous visit counts: no Google signals, no ad storage, no sign-in IDs, and opt-in first in the EU, UK and Switzerland. Usage is metered as role, quality tier, seconds and bytes, never as a profile of a person. The SDKs contain no advertising IDs or ad keys. They’re banned from MOQOM’s code, and if your app uses them, that’s your choice to add.
Participant IP addresses are blanked 30 days after they’re last seen. Media is never stored, and safety signals are pseudonymised, with no addresses or media in them.
The Go and Rust SDKs manage participants, roles, grants, bans and mutes, and stream every join, leave and moderation action live. The Swift SDK has structured logging built in.
Each of these operates in production or in shipped code now. A nightly automated check of the cloud project, which writes a dated report to locked storage, is being switched on next.
| Encryption in transit | TLS 1.3 on every QUIC connection, mutual TLS between relays and the control plane, encrypted-only database connections |
|---|---|
| Encryption at rest | AES-256 on all stored data, with SFrame end-to-end media encryption available per room |
| Media retention | Relayed, never recorded unless you attach a recorder, and every recorder is disclosed to the room |
| Network | Private cluster nodes and a database on a private IP only, with no public address |
| Credentials | No downloadable service account keys. API keys are stored hashed, shown once and revocable |
| Tenant isolation | A key reads only its own tenant's data, and every token is checked against every namespace it touches |
| Audit trail | Google Cloud admin activity logs, kept for 400 days and locked against tampering |
| Billing records | An append-only ledger, kept for 7 years and never edited |
| Infrastructure | Every environment is defined in Terraform and can be rebuilt from it. Deployed images are pinned by digest |
Customers get 30 days’ notice before a new subprocessor handles their data.
| Company | Purpose | Location |
|---|---|---|
| Google Cloud | Hosting: compute, database, storage, logging | United States (us-west1, us-west2) |
| Stripe | Payments, checkout and invoices | United States |
| GitHub | Source code and CI. No customer personal data | United States |
| Hover (Tucows) | Company email, domains and DNS | Canada and United States |
For a security questionnaire, the draft DPA, or a request to access or delete your data, email hello@moqom.cloud. Security issues go to security@moqom.cloud. See also Security and the privacy notice.