Security

Evidence-backed safeguards and a dedicated route for responsible vulnerability disclosure.

Version
2026-08-14.1
Effective
Updated

How the platform is governed

moned uses authenticated BFF sessions, CSRF protection, role-scoped authorization, step-up controls for sensitive administrative actions, append-only decision receipts, private object-storage patterns, and rate limiting where implemented.

Sensitive tax data

Tax identity payloads and identifiers use the private credential-vault encryption path. Only masked display values and non-sensitive status fields are exposed in product views. Tax access is role-scoped; sensitive tax-admin writes require MFA step-up, and corridor promotion, overrides, suspension or release, reporting corrections, and exports use different proposer and approver identities. Audit records must not contain raw identifiers.

Private files fail closed

Sensitive uploads remain quarantined until validation and configured malware scanning succeed. If a general-purpose scanner is unavailable, support evidence remains disabled instead of being accepted without protection.

Responsible disclosure

Do not include credentials or unnecessary personal data, disrupt the service, access data that is not yours, or publish a vulnerability before coordination.

Use the security disclosure form or email security@moned.ai.

Security has limits

No internet service can promise absolute security. This page describes implemented patterns without claiming a certification, audit result, or guarantee that moned has not obtained.

Security | moned