Trust & Security | MOSS
TRUST & SECURITY

We hold ourselves
to the standard
we sell

MOSS is trust infrastructure, so our own security posture is the product. Here is how we protect your data and prove it.

CRYPTOGRAPHY

Provable, not asserted

Post-quantum signatures
Every action signed with ML-DSA-44 (NIST FIPS 204).
Offline verification
Signatures verify without contacting MOSS. The math is the proof.
Tamper-evident chain
Hash-chained, Merkle-rooted logs detect any alteration.
DATA

Your data, your control

Bring your own key
Signing happens in your KMS. MOSS never sees your private keys.
Data residency
Choose US, EU, or APAC, with residency validation and enforcement.
Least privilege
Capability tokens are scoped, time-limited, and single-purpose.
ASSURANCE

Independently checkable

Regulator portal
Time-limited, read-only, scoped access for auditors, with a meta-audit trail.
Compliance mappings
SOC 2, ISO 42001, GDPR controls mapped to evidence.
Responsible disclosure
Found something? security@mosscomputing.com, we respond fast.
ATTESTATIONS

Audited against the same bar

We sell evidence, so we hold ourselves to independent attestation. Current status below.

SOC 2 Type IIIN PROGRESS
Security, availability, and confidentiality controls under audit.
ISO 27001IN PROGRESS
Information security management system implementation underway.
ISO 42001IN PROGRESS
AI management system aligned to the emerging standard for AI governance.
Request our security package, SIG questionnaire, penetration-test summary, and reports under NDA. security@mosscomputing.com →
DESIGN PARTNERS

Selected design partners

We work with a select group of teams running agents in production under real regulatory pressure. They shape the roadmap.

Become a design partner

Put every agent on the record

Request a demo