Your data, handled with real care
We handle sensitive customer data every day: phone numbers, addresses, and conversations. Here's how we protect it, what we collect, and where our compliance work actually stands, in plain language.
Last reviewed: April 17, 2026
The controls behind every account
Encryption, access, data handling, and infrastructure — the four things that keep your customers' data safe.
Where we actually stand
We label what's in place and what's still in progress. No badges we haven't earned.
GDPR
We follow GDPR practices: data export, the right to deletion, and a plain-English privacy policy that says what we collect, why, and how long we keep it.
CCPA
California residents get the same controls: access, export, and deletion of personal information, and a hard rule that we never sell customer data.
SOC 2 Type II
We follow the SOC 2 controls framework today. The formal Type II audit is planned for late 2026 — until it's complete we won't claim certification.
Internal security reviews
Our team runs regular internal security reviews, monitors for vulnerabilities, and applies patches proactively rather than waiting for an incident.
What we collect, and who touches it
The short version of our data practices. The full detail lives in the privacy policy.
Security, asked plainly
Still have a question? Email security@mosco.ai.
Have a security question?
Reporting an issue, reviewing us for a deal, or just want the details? Email security@mosco.ai and a real person will get back to you.
