Read-only. Agentless by default. It never sees what your people type.
A governance tool that creates a new security problem isn't a governance tool. Here is exactly what Moustr touches, what it stores, and what it structurally cannot do.
Where the boundary sits.
Discovery reads service metadata: which services were reached, when and how often. Nothing else crosses.
- Endpoints and devicesNever read
- Files, documents, mailboxesNever read
- Prompts and AI conversationsNever read
- Application content and payloadsNever read
- Individual browsing historiesNever read
Service metadata — which services were reached
↓ Only this
- Resolve to known AI services
- Reconcile with human and vendor sources
- Owner, use, classification, policy
- Evidence, history, export
Identification mode you controlReal name, pseudonym, or no identifier
What we collect, and what we structurally cannot.
Collected
- Service metadata from the sites, devices and cloud platforms you include
- The service resolved, when, and how often — in aggregate
- Answers people give when asked about a system
- A device identifier, in the mode you have selected
- Contract and DPA details you enter or import, and what vendors publish about their products
- Ownership assignments, decisions and their timestamps
- Administrator account details for your own users
Not collected
- Prompt text, uploads or AI conversation content
- File contents, mailboxes or documents
- Keystrokes, screenshots or session recordings
- A browsing history. Domains not yet known as AI are kept only as candidates for classification — the domain name, never a page, a URL or content, and with no identifier on the Anonymous default
- Anything requiring software on an endpoint, to get started
- Rankings, league tables or per-person usage reports of any kind
Agentless by default. No software or agent to install. A company laptop that leaves the building stays covered: coverage is set up once on the device and travels with it. What remains outside reach is an unmanaged personal device, and some platforms can only be covered in part — limits we would rather state here than have discovered in a security review. The three ways traffic reaches Moustr sets out which route fits what.
This is not a surveillance product, and it is built so it can't become one.
Across Europe, employee representatives ask this before anything else — and where co-determination is written into law, as in the DACH countries, the Benelux and the Nordics, they ask it first and they ask it formally. Under the GDPR the question arrives in every market, whatever the local structure is called. The answer here is architectural, not a policy promise.
You choose the identification mode
Three settings, per tenant, changeable at any time. Anonymous — no device or user identifier retained at all, and the setting every new organisation starts on. Pseudonym — a one-way keyed hash using a key you set. The key is unique to your organisation, held outside the database and never shared with anyone else; without it, no identifier is stored at all. Real device name — the plainest and least private, only if you choose it.
Systems, not people
The output is a register of AI systems with named accountable owners. Owners are assigned a responsibility, not caught doing something. Nothing in the product produces a per-person usage report, a ranking or a league table.
The switch is yours, not ours
You start on the most private setting, and only you can move away from it. If you need a guarantee that nobody — including Moustr — can re-identify a device, choose Anonymous.
Every new organisation starts on Anonymous: no device or user identifier is retained. Moving to Pseudonym or Real device name is a deliberate choice you make per tenant, at any time — worth agreeing with your works council before you make it.
We will support your works council consultation directly, including a written description of processing suitable for submission. Where the optional Moustr Agent or flow visibility is being considered, we recommend consulting on each separately — bundling them gives a council a reason to refuse all three.
Data handling.
Hosting, encryption, isolation, access, retention, deletion, export
| Item | Position | Status |
|---|---|---|
| Hosting region | European Union. Data does not leave the EU in normal operation. Region and provider named in the DPA. | CONFIRMED |
| Encryption | Web and API traffic is encrypted in transit (TLS), and backups are encrypted. | CONFIRMED |
| Tenant isolation | Logical separation per customer tenant. | CONFIRMED |
| Access control | Role-based and individually attributed: every user has their own account and role. Moustr staff access to customer data is limited to a small number of named people and used only for support. | CONFIRMED |
| Identification mode | A per-tenant setting you control: no identifier at all, one-way keyed pseudonym using a key you set, or real device name. New organisations start on Anonymous. | ANONYMOUS BY DEFAULT |
| Retention | Set per organisation. Raw activity is kept for 30 days by default, and you can change that. | CONFIRMED |
| Deletion | Deleting an organisation removes its records, evidence and users. | CONFIRMED |
| Export | Your record and evidence are exportable at any time, in a format you keep after the agreement ends. | CONFIRMED |
Certification, stated honestly.
We hold customers to a standard of evidence. It would be difficult to then overstate our own.
| Standard | Where we are | Status |
|---|---|---|
| ISO/IEC 27001 | Certification is planned and not yet held. Our current security practices are described on this page.Target date published once the audit is booked. | PLANNING |
| ISO/IEC 42001 | Certification is planned and not yet held. The product is built to produce the inventory, ownership and evidence the standard asks for. | PLANNING |
| SOC 2 Type II | Not started. Prioritised against customer demand rather than assumed. | NOT HELD |
| GDPR | Processor role, a data processing agreement on request (draft), EU hosting. | IN PLACE |
| Penetration test | Not yet carried out. An independent test is planned; no summary letter exists to share until it has been completed. | TO SCHEDULE |
Moustr provides discovery, reconciliation, workflow and evidence to support AI governance. Moustr does not certify compliance and does not provide legal advice. Regulatory, risk and certification decisions remain yours and your advisers'. Being clear about that boundary is part of being a credible assurance vendor.
Deployment and reversal.
One change to start
One change for a whole site, or a one-time setup per device. No software or agent to install, and no change window for laptops.
First findings within minutes of connecting
Signal starts arriving immediately. A picture worth reviewing builds over days as normal patterns of work appear.
Reversible in one change
Undo the change. No software or agent was installed, so nothing needs uninstalling. Your export is yours to keep.
If you later add the optional Moustr Agent, that is a separate decision, separately consulted, and separately reversible.
Ask for the Data Processing Agreement at hello [at] moustr [dot] com, and put the questions your architect will ask to someone who built it.
Still have questions your architect will ask?
Ten minutes with someone who built it, not a sales engineer reading from a sheet.
Request free trial