Moyo logo
Buy a report

Security

How we handle assessments and data

Last updated: August 4, 2026

Moyo is built to produce analytic clarity, not performative intrusion. The security of your relationship with us depends on authorization, scope, and careful handling of each data class: marketing contacts, public-source material, customer confidential inputs, and generated findings.

Operator: SenTeGuard Inc.. See also Authorized use · Privacy · Terms.

  1. 01

    Authorization first

    No silent red-teaming

    Outside-in work uses lawful public sources after form or engagement confirmation. White-box access to customer-owned systems requires written authorization and defined scope.

  2. 02

    Data separation

    Classes with different rules

    Marketing contact data, public-source scan data, customer-provided confidential data, and generated findings are distinguished in our privacy policy and are not treated as a single undifferentiated store.

  3. 03

    Least access

    Need-to-know delivery

    Engagement materials and confidential corpora are limited to personnel and processors required for the engagement. Customer confidential inputs are not used for general marketing audiences.

  4. 04

    Retention

    Documented deletion

    Working sets and findings follow retention periods agreed for the engagement, with deletion or de-identification when the period ends, subject to legal hold requirements.

  5. 05

    Transport & hosts

    Modern hosting stack

    The public site is served over HTTPS via our hosting provider. API routes that accept scan requests validate input and do not accept confidential file uploads from anonymous visitors.

  6. 06

    Incident posture

    Contact and escalation

    Suspected security issues involving Moyo or our handling of customer data should be reported through contact with sufficient detail for investigation. We prioritize authorized customers under engagement agreements.

What this page is not

This summary is not a SOC 2 report, penetration test certificate, or guarantee of invulnerability. It describes how we intend to operate assessments and product systems so that trust is earned through process, not slogans.