Security & Privacy Policy

How MoonshotBI protects your data, enforces access controls, and meets regulatory obligations.

Last reviewed: March 2026 · Version 1.0

Encryption — Transit & At Rest
Enforced
  • All data in transit encrypted via TLS 1.3 minimum (enforced at the platform/CDN layer).
  • All data at rest encrypted via AES-256 (Base44 managed infrastructure).
  • Database backups encrypted with the same AES-256 standard before storage.
  • Encryption keys managed via platform KMS; no application-level plaintext key exposure.
Role-Based Access Control (RBAC)
Enforced
  • Three roles: admin (full access), founder (owns own valuations), investor (view-only, consent-gated).
  • Founders: create, read, update, delete their own Valuation records.
  • Investors: read-only access — and only to valuations where the founder has given explicit consent.
  • Admins: full platform access including ROPA registry, audit logs, and QA tools.
  • Role assignment controlled by admins only; new users default to the 'founder' role.
Founder Privacy & Investor Consent Gate
Enforced
  • Founder personal data (background, financials, contact info) is never surfaced to investors without explicit opt-in.
  • Consent is recorded per-valuation in the ConsentRecord entity with timestamp and action log.
  • Founders can revoke consent at any time; revocation is immediate and logged.
  • Investor-facing views render only aggregated, non-personally-identifiable valuation data by default.
AI Model Training Data Anonymisation
Policy
  • No personally identifiable information (PII) is ever passed to AI model training pipelines.
  • LLM prompts use anonymised placeholders: company names, founder names, and contact details are stripped before prompt construction.
  • Valuation narratives generated by LLMs are stored per-record and not used as training data without separate explicit consent.
  • All AI inference calls are stateless — the LLM provider retains no session context between requests.
GDPR Compliance
Active
  • Article 30 Record of Processing Activities (ROPA) maintained — see the ROPA Registry page (admin only).
  • Legal bases documented per processing activity: contract, consent, or legitimate interest.
  • Data subject rights supported: access (export), rectification (edit profile), erasure (deletion request flag), portability.
  • Data retention policy: active valuations retained while account is active; deleted on account closure after 30-day grace period.
  • Data Protection Officer (DPO) contact available via privacy@moonshotbi.ai.
Infrastructure & Platform Security
Platform-Guaranteed
  • Hosted on Base44 managed infrastructure with 99.5% uptime SLA.
  • Network perimeter protected by WAF (Web Application Firewall) and DDoS mitigation.
  • All API endpoints require authenticated session tokens; unauthenticated requests return 401.
  • Backend functions run in isolated Deno sandboxes — no shared memory between tenants.
  • Dependency supply-chain scanning via automated CI checks.
SOC 2 Type II Roadmap
In Progress
  • Target: SOC 2 Type II certification within 12 months of GA launch.
  • Trust Service Criteria in scope: Security (CC), Availability (A), Confidentiality (C), Privacy (P).
  • Controls mapping underway against CC6 (Logical & Physical Access), CC7 (System Operations), CC9 (Risk Mitigation).
  • Penetration testing scheduled quarterly; findings tracked in internal risk register.
  • Audit logging enabled for all create/update/delete operations on sensitive entities.

Questions or data requests?

Contact our Data Protection Officer at privacy@moonshotbi.ai.

To exercise your GDPR rights (access, rectification, erasure, portability), submit a request via your account settings or email the DPO directly.