Mood nook sp. z o.o. · effective 2026-08-11

Security Overview

How the platform protects data: isolation, access control, encryption, auditing, backups and responsible disclosure.

1. Architecture and isolation

  • Every record is stamped with an account identifier and every read and write passes through a tenant scope guard.
  • Row-level security is enabled on all customer tables; a row belonging to another tenant is reported as not found rather than forbidden.
  • Event fan-out, webhooks and streaming interfaces are filtered by the same tenant scope.
  • Cross-tenant regression tests run in the automated test suite on every change.

2. Access control

  • Access is resolved from a role baseline, then grant permission sets, then restrict permission sets, then schema policies, with deny taking precedence.
  • Field-level security limits readable and writable fields per role and per token.
  • API tokens carry explicit scopes; a token can only reach the models, fields and operations it was granted.
  • Roles are stored in a dedicated table and evaluated server-side, never derived from client state.

3. Data protection

  • TLS 1.2 or higher in transit; encryption at rest on managed storage.
  • Passwords and API token secrets stored as salted hashes only, never returned by any interface.
  • Rich text is sanitised on write and again on render.
  • Uploaded media is served through scoped storage policies.

4. Auditability and recovery

  • Append-only audit log of administrative and content mutations with actor, before and after values.
  • Immutable version snapshots allow rollback of an entry to any prior revision.
  • Automated backups with tested restore procedures and separated environments for development, staging and production.

5. Responsible disclosure

Report a suspected vulnerability to security@xeper.io. Please give us reasonable time to remediate before public disclosure, do not access or modify data belonging to others, and do not run denial of service tests. We acknowledge reports within 3 business days and will keep you updated until closure. We will not pursue legal action against researchers who follow this policy in good faith.

Questions about this document: legal@xeper.io. This text is provided for transparency and does not constitute legal advice.

Back to the legal centre