Security

Engineered for clients whose IT review actually has questions.

The case materials uploaded for a Mootly session are among the most sensitive documents your firm or program possesses. We treat them that way. This page is the high-level overview — the full security whitepaper is available under NDA.

Data handling

Ephemeral processing

Uploaded briefs, opposition filings, and supporting documents are processed in memory. They are never written to persistent disk. The processing environment is destroyed at the end of the session.

What we retain

We retain the structured case profile (tension map, anticipated questions), vector embeddings of the document chunks (which cannot be reverse-engineered into readable text), and the session transcript and audio. Source documents themselves are deleted at session end.

Retention controls

Default retention: 30 days. Org admins can configure: 7 days, 30 days, 90 days, or zero-retention mode. In zero-retention mode, all session artifacts are deleted at session end and no replay is possible.

No model training on customer data

Customer-uploaded materials are never used to train Mootly’s models or any third party’s models. This is contractual, not aspirational. The master agreement contains a no-training warranty.

Encryption

All data in transit is encrypted with TLS 1.3. All data at rest is encrypted with AES-256. The audio stream for live sessions is encrypted end-to-end through the WebRTC channel.

Access control

Three-tier hierarchy: Org Admin (manages billing and seats) → Team Admin (manages a practice group or course) → Practitioner / Student (runs sessions, sees their own debriefs). Audit logs track every access. SSO (SAML 2.0 + OIDC) on firm-wide and institution licenses.

Sub-processors

Full sub-processor list available under NDA. Major sub-processors: Anthropic (LLM inference), Vapi (voice orchestration), Deepgram (speech-to-text), ElevenLabs (text-to-speech), Vercel (web hosting), Supabase (database). Customers receive 30-day notice of any new sub-processor addition.

Vulnerability disclosure

Found a security issue? Email security@mootly.ai with details. We commit to acknowledging within one business day and to a coordinated disclosure timeline. Bug bounty program in development.

Status & transparency

Status page at status.mootly.ai (Phase C deliverable). Quarterly security overview newsletter for current customers.

For your IT or InfoSec team: request the full security whitepaper, sub-processor list, and Mootly DPA at security@mootly.ai. Standard turnaround: one business day.

Talk to your IT team

Hand them this page. They’ll know what to ask next.

Request a demo