Engineered for clients whose IT review actually has questions.
The case materials uploaded for a Mootly session are among the most sensitive documents your firm or program possesses. We treat them that way. This page is the high-level overview — the full security whitepaper is available under NDA.
Data handling
Ephemeral processing
Uploaded briefs, opposition filings, and supporting documents are processed in memory. They are never written to persistent disk. The processing environment is destroyed at the end of the session.
What we retain
We retain the structured case profile (tension map, anticipated questions), vector embeddings of the document chunks (which cannot be reverse-engineered into readable text), and the session transcript and audio. Source documents themselves are deleted at session end.
Retention controls
Default retention: 30 days. Org admins can configure: 7 days, 30 days, 90 days, or zero-retention mode. In zero-retention mode, all session artifacts are deleted at session end and no replay is possible.
No model training on customer data
Customer-uploaded materials are never used to train Mootly’s models or any third party’s models. This is contractual, not aspirational. The master agreement contains a no-training warranty.
Encryption
All data in transit is encrypted with TLS 1.3. All data at rest is encrypted with AES-256. The audio stream for live sessions is encrypted end-to-end through the WebRTC channel.
Access control
Three-tier hierarchy: Org Admin (manages billing and seats) → Team Admin (manages a practice group or course) → Practitioner / Student (runs sessions, sees their own debriefs). Audit logs track every access. SSO (SAML 2.0 + OIDC) on firm-wide and institution licenses.
Sub-processors
Full sub-processor list available under NDA. Major sub-processors: Anthropic (LLM inference), Vapi (voice orchestration), Deepgram (speech-to-text), ElevenLabs (text-to-speech), Vercel (web hosting), Supabase (database). Customers receive 30-day notice of any new sub-processor addition.
Vulnerability disclosure
Found a security issue? Email security@mootly.ai with details. We commit to acknowledging within one business day and to a coordinated disclosure timeline. Bug bounty program in development.
Status & transparency
Status page at status.mootly.ai (Phase C deliverable). Quarterly security overview newsletter for current customers.
For your IT or InfoSec team: request the full security whitepaper, sub-processor list, and Mootly DPA at security@mootly.ai. Standard turnaround: one business day.