Security at Morvero

Last updated: 20 July 2026

Morvero collects product usage and feedback for enterprise application portfolios. This page describes, concretely, how that data is protected. It lists what we do today — not aspirations. Where a control is on our roadmap rather than in place, it says so explicitly.

Compliance status. Morvero is not yet SOC 2 attested. We maintain an internal control mapping against the SOC 2 Trust Services Criteria and are preparing for a Type I audit; this page will be updated when an attestation is available. Ask security@morvero.com for the current readiness summary.

Anonymous by design

Encryption

Authentication & access control

Tenant isolation & auditability

Data lifecycle

Application security

Subprocessors

ProviderPurposeData involved
RailwayApplication hosting & managed PostgreSQLAll workspace data
Postmark (ActiveCampaign)Transactional emailAdmin email addresses, email content
AnthropicAI features (backlog copilot, theme summaries) — only when your plan has AI features enabledFeedback text sent for summarization

Reporting a vulnerability

We want to hear about it. Email security@morvero.com with reproduction steps; machine-readable details are published at /.well-known/security.txt. We commit to acknowledging reports within 3 business days. Please avoid accessing other tenants' data while researching — use a free workspace of your own.