Platform security
Security Policy
MoryaOS treats account authority, organization isolation, privacy-safe public projections, secure recovery, and honest degraded states as core security boundaries.
Last updated: 2026-08-26
Security practices
The platform uses server-side authorization, scoped organization access, protected authentication flows, bounded public projections, input validation, security headers, rate limits where applicable, and privacy-aware error and telemetry handling.
Security controls are continuously reviewed. Source checks, local tests, and a successful deployment do not by themselves prove every hosted provider or runtime control is healthy.
Protect your account
Use a unique password, keep recovery channels under your control, review unexpected sign-in or organization activity, and report suspected account takeover quickly. MoryaOS will not ask for an OTP or password by email or phone.
Report a security concern
Send suspected vulnerabilities to security@moryaos.com. Include the affected URL or feature, a concise description, safe reproduction steps, and the minimum evidence needed to validate the issue. Remove secrets, tokens, personal data, and unrelated account information before sending.
Need help with this policy?
Contact MoryaOS at admin@moryaos.com. Never include a password, OTP, recovery code, or access token.
