Legal & trustTrust center

Trust & security

Current implementation facts, clear assurance boundaries, and routes for incidents and good-faith vulnerability reports.

Publication draft — pending counsel and business approvalProduction publication is blocked until task t16 records legal and business approval.

Current architecture

Mosaic is a Next.js application backed by Postgres. LiveKit is a separate realtime service. Authentication supports Mosaic email and password plus conditional Google and Microsoft sign-in. Signed-in identity and workspace or project membership checks bound application access.

Auth.js sessions have a seven-day maximum. Local passwords use scrypt hashes with per-user salts. Sensitive service credentials are configured server-side, and project-scoped AI provider credentials use encrypted envelopes in the reviewed implementation.

Data lifecycle controls

Bounded cleanup rules reduce selected operational records, including raw usage, verification records, office invites, lifecycle diagnostics, rate-limit buckets, and ephemeral room data. Durable account and project data does not currently share one general time-based purge rule.

Contains pending assurances

Assurance status

Mosaic does not claim SOC 2, ISO certification, a penetration-test attestation, an uptime SLA, a fixed data region, or another assurance without dated evidence. Provider certifications apply to those providers and do not certify Mosaic.

Provider environment configuration, regions, backups, operating practice, contracts, and retention remain pending confirmation. These pages describe reviewed code behavior, not an independent audit.

Microsoft identity access

Mosaic's current Microsoft request is delegated access for the signed-in person: openid, profile, email, and User.Read. Publisher verification is not yet claimed. If completed later, it would confirm publisher identity rather than certify Mosaic's security or compliance.

Contains pending assurances

Incidents and vulnerability reporting

Send suspected security incidents or good-faith vulnerability reports to security@mosaicscreens.app. Avoid accessing or changing other people's data, do not disrupt the service, and do not include credentials or unnecessary personal information.

Mailbox monitoring, acknowledgement targets, testing authorization, safe-harbor terms, incident response, and disclosure coordination remain pending operational and legal approval. No response-time promise is made.

Document history

Change history

  1. Draft 0.1 ·

    Initial fact-checked publication draft. It is not effective and has not been approved as a legal or contractual commitment.