MOZAIC Core
Security & Data Protection
What actually protects your firm's and your clients' data — not a marketing checklist.
How Your Data Is Protected
Tenant Isolation
Each organisation's data is isolated from every other organisation at the application layer. One firm's leads, clients and documents are never visible to another.
Signed, Time-Limited Document Access
Private documents are never publicly accessible. Every file is served through a signed URL that expires, not a permanent public link.
EU-Hosted Infrastructure
Data is processed and stored in the EU via Supabase and Vercel, following GDPR data-minimisation principles.
Encrypted Storage
Files are stored in encrypted Supabase Storage, with access controlled at the organisation level.
Audit Logging
Sensitive platform-admin actions — impersonation, role changes, deletions — are written to an audit log before they take effect.
A Note on Honesty
We do not claim SOC 2, ISO 27001 or any third-party certification we have not actually obtained. Everything on this page reflects how the platform is built today.
