Security

Security you can bet your business on

Practical, layered safeguards for accounts, customer data, payments, integrations, and production operations.

HTTPS2FASigned webhooksRate limitingDDoS protection

Security by design

Every layer of the platform is built with security as a first principle.

๐Ÿ”

Encryption in transit and at rest

HTTPS protects traffic in transit. Our hosting and database providers apply encryption at rest to the infrastructure they manage.

๐Ÿ›ก๏ธ

Access controls

Protected routes require authenticated sessions, sensitive administration routes require an administrator role, and records are scoped to their owner where applicable.

๐Ÿ”’

Security-focused infrastructure

The service runs on managed infrastructure with platform DDoS protection, isolated deployments, encrypted transport, and controlled environment variables. MansaMusaAI does not currently claim its own SOC 2 certification.

๐ŸŒ

Privacy and UK GDPR

Our controls are designed to support UK GDPR responsibilities. Customers remain responsible for lawful collection, notices, consent, and their own use of personal data.

๐Ÿงช

Vulnerability management

We scan dependencies, review exposed routes, monitor production errors, and provide a channel for responsible vulnerability reports. Findings are prioritised by severity and impact.

๐Ÿ“‹

Security audit records

The application records important account-security events such as successful and failed logins, lockouts, password changes, email changes, and session revocation.

๐Ÿ”‘

Multi-factor authentication

Accounts can enable TOTP two-factor authentication and receive backup codes. Login throttling, lockouts, breached-password checks, and session revocation add further protection.

๐Ÿ—๏ธ

Tenant separation

Application queries enforce user, team, or administrator ownership rules. We continue to test these boundaries as new features are added.

Our practices

What we do every day to keep you safe

Security is ongoing work. These are the controls currently implemented and maintained in the service.

  • Dependency vulnerability review and patching
  • Signed Stripe and Twilio webhook verification
  • Secrets kept in server-side environment variables
  • Role and record-ownership checks on sensitive routes
  • Rate limits on login, registration, AI, and public-write endpoints
  • Vercel platform-level DDoS protection
  • Security headers and strict request validation
  • Production error monitoring and audit records
๐Ÿ”

Responsible disclosure

Found a security vulnerability? Please include the affected URL, steps to reproduce, and potential impact. Do not access other people's data or disrupt the service while testing.

Report a vulnerability

Ready to deploy with confidence?

Review our privacy policy and enable two-factor authentication after creating your account.