Security
Security you can bet your business on
Practical, layered safeguards for accounts, customer data, payments, integrations, and production operations.
Security by design
Every layer of the platform is built with security as a first principle.
Encryption in transit and at rest
HTTPS protects traffic in transit. Our hosting and database providers apply encryption at rest to the infrastructure they manage.
Access controls
Protected routes require authenticated sessions, sensitive administration routes require an administrator role, and records are scoped to their owner where applicable.
Security-focused infrastructure
The service runs on managed infrastructure with platform DDoS protection, isolated deployments, encrypted transport, and controlled environment variables. MansaMusaAI does not currently claim its own SOC 2 certification.
Privacy and UK GDPR
Our controls are designed to support UK GDPR responsibilities. Customers remain responsible for lawful collection, notices, consent, and their own use of personal data.
Vulnerability management
We scan dependencies, review exposed routes, monitor production errors, and provide a channel for responsible vulnerability reports. Findings are prioritised by severity and impact.
Security audit records
The application records important account-security events such as successful and failed logins, lockouts, password changes, email changes, and session revocation.
Multi-factor authentication
Accounts can enable TOTP two-factor authentication and receive backup codes. Login throttling, lockouts, breached-password checks, and session revocation add further protection.
Tenant separation
Application queries enforce user, team, or administrator ownership rules. We continue to test these boundaries as new features are added.
Our practices
What we do every day to keep you safe
Security is ongoing work. These are the controls currently implemented and maintained in the service.
- Dependency vulnerability review and patching
- Signed Stripe and Twilio webhook verification
- Secrets kept in server-side environment variables
- Role and record-ownership checks on sensitive routes
- Rate limits on login, registration, AI, and public-write endpoints
- Vercel platform-level DDoS protection
- Security headers and strict request validation
- Production error monitoring and audit records
Responsible disclosure
Found a security vulnerability? Please include the affected URL, steps to reproduce, and potential impact. Do not access other people's data or disrupt the service while testing.
Report a vulnerabilityReady to deploy with confidence?
Review our privacy policy and enable two-factor authentication after creating your account.