Security

Bounded authority and verifiable execution.

Security practices, responsible disclosure, and current assurance status.

Security approach

MODU is designed around bounded capabilities, explicit authority, verifiable receipts, and separation between human credentials, machine credentials, private control paths, and public application surfaces.

  • Least authority: integrations receive only the scopes required for their documented job.
  • Scoped writes: reversible sourced work can execute automatically inside a bound workflow; legal, financial, identity, and destructive consequences remain explicit.
  • Secret separation: passwords, tokens, OTPs, recovery codes, and private keys are not intended for public repositories, public logs, or company spreadsheets.
  • Verification: operational work is expected to produce evidence that can be checked rather than relying only on a success message.
  • Human gates: CAPTCHA, MFA, passkeys, legal terms, and payments pause a workflow without inventing or bypassing the missing authority.
  • Data boundaries: personal, health, family, company, and client information are treated as distinct classes.

Responsible disclosure

Send a good-faith security report to contact@moduindustries.ca (Security). Include the affected service, reproduction steps, impact, and a safe way to contact you. Do not include passwords, private keys, personal data, or unrelated customer information.

Please do not conduct denial-of-service testing, social engineering, physical intrusion, persistence, data destruction, or testing against third-party systems without written authorization. A public bug-bounty payment is not promised unless agreed in writing before work begins.

Current assurance status

This page describes working practices and direction. MODU does not claim SOC 2, ISO 27001, HIPAA, government clearance, or another independent certification that has not been formally issued.