Mopbe
HomeFeaturesIndustriesPricingAboutBlog
Sign inRequest demo
All legal documents

Security & Trust Statement

Verified design controls and limits of assurance.

Owner-approved — effective September 27, 2026

Version 2026-09-27-owner-approved-2. Effective date: 2026-09-27.

In this document

  1. Scope
  2. Application controls
  3. Data and infrastructure
  4. Recovery and retention
  5. Security reporting
  6. Assurance gaps

Scope

This is a code-based review statement, not a certification, penetration-test attestation or guarantee. Hosted configuration requires separate verification. Mopbe is part of the EVDATI All-in-One Business Ecosystem and can be used standalone.

Application controls

The inspected account portal uses server-side organization/brand/location authorization, PostgreSQL row-level policy design and separate application/authentication credentials. Session cookies, request checks, password reset and audit records are implemented. Controls depend on deployment configuration and testing; public demo codes are not equivalent to a unique individual identity.

Data and infrastructure

The release targets Render web hosting and PostgreSQL; isolated local testing uses SQLite. HTTPS is required for hosted session settings. Application code does not establish end-to-end encryption, customer-managed keys, encryption of every local export, or provider certifications. Restrict and protect downloaded backups independently.

Recovery and retention

Following expiration or termination, customers have up to 30 days to access and/or export available Customer Data, subject to law, security requirements, technical availability and any different written agreement. After that period, EVDATI is not obligated to retain data for retrieval unless legally required or expressly agreed. Customer Data will be deleted or properly de-identified from active production systems within 90 days, subject to legitimate legal, regulatory, tax/accounting, litigation-hold, dispute, fraud-prevention, security-investigation and contractual-enforcement requirements. Exception records remain protected, restricted to the justified purpose and reviewed for continued necessity.

Residual copies of Customer Data may remain temporarily in backup or disaster-recovery systems after deletion from active systems. Such copies are isolated from ordinary business use and are deleted or overwritten in accordance with our normal backup lifecycle, subject to applicable legal requirements. No specific backup-retention duration is represented here; the production lifecycle remains to be verified.

Logical backup/restore tooling exists. Current hosted backup coverage, restore frequency and recovery objectives require verification before a service commitment. Own-server status samples show observed checks only; they do not prove continuous independent uptime.

Security reporting

Contact support@evdati.com with a concise description and safe reproduction steps. Do not include passwords, reset links or unrelated customer data. Do not exploit, exfiltrate or destructively test without written permission. Incident response follows applicable law and the executed DPA; no unverified response-time guarantee is offered.

Assurance gaps

[LEGAL/OPERATIONAL CONFIRMATION REQUIRED]: live configuration, provider region/encryption evidence, independent testing, incident runbook, restore cadence, retention automation and access reviews. No SOC 2, ISO 27001, PCI DSS or universal compliance certification is claimed.

Mopbe

Part of the EVDATI All-in-One Business Ecosystem.

Product

  • Features
  • Industries
  • Pricing
  • Contact
  • Blog

Company

  • About
  • Support
  • Service status

Legal

  • Terms
  • Privacy
  • Cookies
  • Security
  • Legal Center

© 2026 EVDATI Innovated LLC. All rights reserved.

Mopbe is part of the EVDATI All-in-One Business Ecosystem.