Skip to content
m0vom0vo

Security

Security built for sensitive product and commercial data

Vendor contracts, lifecycle risk, and inventory choices are not marketing copy—they are internal intelligence. m0vo is designed so each organization’s catalog stays isolated, secrets and database files are encrypted, and sessions expire after configurable inactivity.

What you get

  • Per-organization catalog isolation (vendors, products, capabilities, contracts)
  • AES-256-GCM sealed database file at rest
  • SSO client secrets encrypted at rest (AES-GCM) with server-side keys
  • HTTPS-only, signed session cookies with idle and absolute timeout controls
  • Role-based access: platform and org roles gate reads, writes, and admin
  • Org admins can export only their org’s data as CSV—not other tenants

Organization isolation by design

Multi-org isolation ensures data is always separated. List, search, discover, and contract workflows use the active org context. Switching organizations changes what you see—there is no shared global product list across customers or business units that should not share data.

Encryption by default

m0vo is built from the ground up with encrypted data and secured protocols. Utilizing an authenticated AES-256-GCM sealed database at rest, and SSO client secrets use the same class of AES-GCM protection.

Sessions that expire when people walk away

Idle and absolute session lifetimes are configurable by minutes. After inactivity, the session is cleared and users must sign in again—supporting desk-sharing and compliance expectations without a separate solution.

Least privilege for day-to-day work

Platform admins, editors, and viewers—and org admin/member/reader roles—limit who can change catalog data, manage members, or export.

More platform capabilities