TLS 1.3 on every media connection
Shipped- QUIC and WebTransport carry TLS 1.3 as part of the protocol, so no media connection is ever in plaintext.
- Raw QUIC and WebTransport share one UDP port, so there's only one surface to harden and monitor.
MOQOM builds in security work that would otherwise fall to your application. Every item below is labelled shipped or planned, so you know exactly what you're getting today.
* Built to scale: a Rust media plane and a Go control plane, each scaling out horizontally. Measured in lab, tested to 6,000 viewers on one 4-vCPU relay with zero loss; pending further load testing.
On the network, a man-in-the-middle or an eavesdropper gets nothing usable from MOQOM. What remains is stated plainly: relays can see track names, sizes and timing, and when end-to-end encryption is off, the relay operator can see media, as with every SFU and every MoQ relay.
The IETF MoQ transport draft deliberately leaves policy to the people who deploy it. These are the parts MOQOM fills in for you.
| Concern | MOQOM ships | IETF draft-ietf-moq-transport |
|---|---|---|
| Transport encryption | TLS 1.3 on every connection | Required, because MoQ runs over QUIC or WebTransport |
| Authorization | Signed, scoped, short-lived tokens checked on every request | Defines how a token is carried. What it contains and how it's checked are left to the deployment |
| Media payload encryption | SFrame, AES-256-GCM by default | Specified separately and optional: draft-ietf-moq-secure-objects |
| Token bound to the device | Every token, to a hardware key in the Secure Enclave, enforced by every relay | Not specified |
| Revoking a live session | A ban closes the open connection | Not specified. Left to the application |
| Relay ↔ control-plane auth | Mutual TLS 1.3, plus a per-relay credential | Out of scope |
| Multi-tenant isolation | Tenant, room and grants checked for every namespace | Out of scope |
Open-source MoQ relays such as moq-rs, Cloudflare's MoQ relay and Meta's moxygen implement versions of the same transport drafts. How each handles authorization, payload encryption and revocation is set out in its own documentation, and we encourage you to compare it with the list above. This table describes the standard, not any other product. It reflects our reading of draft-ietf-moq-transport-19 as of October 2026.
Please report security issues privately to security@moqom.cloud, with enough detail for us to reproduce them.
Our HackerOne program launches as a vulnerability disclosure program. Cash bounties are funded by donations to the open-source projects until paying customers adopt MOQOM. Until then, every valid report gets public credit and our thanks — in the hall of fame and release notes — and we'll send you something: swag in the mail or a tip to your crypto wallet.
The HackerOne program isn't open yet. Until it is, email security@moqom.cloud. You can support the open-source projects through donations ↗.
For SOC 2, ISO 27001, GDPR and PCI status, and our subprocessors, see Compliance.