Bulk-extraction protection
Auditing and circuit breakers that detect and halt anomalous mass access.
Security & data ownership
Each customer’s data lives in an isolated environment. Authentication via OAuth2. All user-supplied content is sanitised. External calls are rate-limited and logged with cost tracking. Backups are automatic. Hosted on Google Cloud, region europe-west4 (the Netherlands).
Who may see and change what is part of your model, expressed over the relationships that already exist in it — “a case handler works with the dossiers of their own clients, and everything beneath them”.
Access spreads along those relations however far they run, and rules can depend on a record’s own state — checked against the state a change would produce, not the one it started from. Lists, searches and pages show only what a user may see; a change the model doesn’t permit is refused; the interface asks the server what is allowed, so no button is offered that will then be rejected.
And because permissions are stored rather than guessed, we can answer not only who may see a record but along which path they were granted it.
Access control decides which records you may open, not every detail a record mentions about what it links to — a related record’s display name travels with the record that links to it. Filtering that would cost an access check per link per row. So it is a rule we design your model against instead: anything whose very existence is confidential doesn’t get linked to a record its reader can open.
Every customer runs on the same engine, so every hardening measure protects everyone at once — a level of sustained attention no single custom-built application can afford.
Auditing and circuit breakers that detect and halt anomalous mass access.
File storage in a location you control; the platform holds keys, never content.
Data processing agreement, backup and recovery terms, and incident procedure available on request at info@mosterd.com.
We are not ISO-certified and won’t claim to be before we are.