Moustr/Security and architectureback to top ↑
SECURITY AND ARCHITECTURE

Read-only. Agentless by default. It never sees what your people type.

A governance tool that creates a new security problem isn't a governance tool. Here is exactly what Moustr touches, what it stores, and what it structurally cannot do.


Where the boundary sits.

Discovery reads service metadata: which services were reached, when and how often. Nothing else crosses.

INSIDE YOUR PERIMETER Endpoints and devices Files, documents, mailboxes Prompts and AI conversations Application content and payloads Individual browsing histories NEVER READNEVER READ NEVER READNEVER READ NEVER READ Service metadata — which services were reached ONLY THIS MOUSTR — EU PLATFORM Resolve to known AI services Reconcile with human and vendor sources Owner, use, classification, policy Evidence, history, export Identification mode you control Real name, pseudonym, or no identifier
Inside your perimeter
  • Endpoints and devicesNever read
  • Files, documents, mailboxesNever read
  • Prompts and AI conversationsNever read
  • Application content and payloadsNever read
  • Individual browsing historiesNever read

Service metadata — which services were reached

↓ Only this

Moustr — EU platform
  • Resolve to known AI services
  • Reconcile with human and vendor sources
  • Owner, use, classification, policy
  • Evidence, history, export

Identification mode you controlReal name, pseudonym, or no identifier

What we collect, and what we structurally cannot.

Collected

  • Service metadata from the sites, devices and cloud platforms you include
  • The service resolved, when, and how often — in aggregate
  • Answers people give when asked about a system
  • A device identifier, in the mode you have selected
  • Contract and DPA details you enter or import, and what vendors publish about their products
  • Ownership assignments, decisions and their timestamps
  • Administrator account details for your own users

Not collected

  • Prompt text, uploads or AI conversation content
  • File contents, mailboxes or documents
  • Keystrokes, screenshots or session recordings
  • A browsing history. Domains not yet known as AI are kept only as candidates for classification — the domain name, never a page, a URL or content, and with no identifier on the Anonymous default
  • Anything requiring software on an endpoint, to get started
  • Rankings, league tables or per-person usage reports of any kind

Agentless by default. No software or agent to install. A company laptop that leaves the building stays covered: coverage is set up once on the device and travels with it. What remains outside reach is an unmanaged personal device, and some platforms can only be covered in part — limits we would rather state here than have discovered in a security review. The three ways traffic reaches Moustr sets out which route fits what.

EMPLOYEE MONITORING

This is not a surveillance product, and it is built so it can't become one.

Across Europe, employee representatives ask this before anything else — and where co-determination is written into law, as in the DACH countries, the Benelux and the Nordics, they ask it first and they ask it formally. Under the GDPR the question arrives in every market, whatever the local structure is called. The answer here is architectural, not a policy promise.

You choose the identification mode

Three settings, per tenant, changeable at any time. Anonymous — no device or user identifier retained at all, and the setting every new organisation starts on. Pseudonym — a one-way keyed hash using a key you set. The key is unique to your organisation, held outside the database and never shared with anyone else; without it, no identifier is stored at all. Real device name — the plainest and least private, only if you choose it.

Systems, not people

The output is a register of AI systems with named accountable owners. Owners are assigned a responsibility, not caught doing something. Nothing in the product produces a per-person usage report, a ranking or a league table.

The switch is yours, not ours

You start on the most private setting, and only you can move away from it. If you need a guarantee that nobody — including Moustr — can re-identify a device, choose Anonymous.

Anonymous by default

Every new organisation starts on Anonymous: no device or user identifier is retained. Moving to Pseudonym or Real device name is a deliberate choice you make per tenant, at any time — worth agreeing with your works council before you make it.

We will support your works council consultation directly, including a written description of processing suitable for submission. Where the optional Moustr Agent or flow visibility is being considered, we recommend consulting on each separately — bundling them gives a council a reason to refuse all three.

Data handling.

Hosting, encryption, isolation, access, retention, deletion, export
ItemPositionStatus
Hosting regionEuropean Union. Data does not leave the EU in normal operation. Region and provider named in the DPA.CONFIRMED
EncryptionWeb and API traffic is encrypted in transit (TLS), and backups are encrypted.CONFIRMED
Tenant isolationLogical separation per customer tenant.CONFIRMED
Access controlRole-based and individually attributed: every user has their own account and role. Moustr staff access to customer data is limited to a small number of named people and used only for support.CONFIRMED
Identification modeA per-tenant setting you control: no identifier at all, one-way keyed pseudonym using a key you set, or real device name. New organisations start on Anonymous.ANONYMOUS BY DEFAULT
RetentionSet per organisation. Raw activity is kept for 30 days by default, and you can change that.CONFIRMED
DeletionDeleting an organisation removes its records, evidence and users.CONFIRMED
ExportYour record and evidence are exportable at any time, in a format you keep after the agreement ends.CONFIRMED

Certification, stated honestly.

We hold customers to a standard of evidence. It would be difficult to then overstate our own.

StandardWhere we areStatus
ISO/IEC 27001Certification is planned and not yet held. Our current security practices are described on this page.Target date published once the audit is booked.PLANNING
ISO/IEC 42001Certification is planned and not yet held. The product is built to produce the inventory, ownership and evidence the standard asks for.PLANNING
SOC 2 Type IINot started. Prioritised against customer demand rather than assumed.NOT HELD
GDPRProcessor role, a data processing agreement on request (draft), EU hosting. IN PLACE
Penetration testNot yet carried out. An independent test is planned; no summary letter exists to share until it has been completed. TO SCHEDULE

Moustr provides discovery, reconciliation, workflow and evidence to support AI governance. Moustr does not certify compliance and does not provide legal advice. Regulatory, risk and certification decisions remain yours and your advisers'. Being clear about that boundary is part of being a credible assurance vendor.

Deployment and reversal.

One change to start

One change for a whole site, or a one-time setup per device. No software or agent to install, and no change window for laptops.

First findings within minutes of connecting

Signal starts arriving immediately. A picture worth reviewing builds over days as normal patterns of work appear.

Reversible in one change

Undo the change. No software or agent was installed, so nothing needs uninstalling. Your export is yours to keep.

If you later add the optional Moustr Agent, that is a separate decision, separately consulted, and separately reversible.

Running a security review right now?

Ask for the Data Processing Agreement at hello [at] moustr [dot] com, and put the questions your architect will ask to someone who built it.

Still have questions your architect will ask?

Ten minutes with someone who built it, not a sales engineer reading from a sheet.

Request free trial