Security
Security as a product feature, not a checkbox.
This page is maintained by Mortevo Audit and describes the security controls currently enabled on the platform. It is not a certification.
Mortevo Audit runs on managed cloud infrastructure with a shared-responsibility model. The controls below describe what the platform enforces; some items require configuration by your organisation's administrator (marked Customer).
Encryption
- Data in transit is encrypted with TLS 1.2 or higher on all endpoints.
- Data at rest is encrypted using industry-standard AES-256 by our cloud database provider.
- Backup storage is encrypted at rest.
Authentication & access
- Email and password authentication with a 12-character minimum policy.
- Time-based one-time password (TOTP) multi-factor authentication.
- AAL2 (multi-factor) is enforced on privileged operations, including member invitation and review outcome confirmation.
- Session revocation on member suspension or removal is automatic.
- Role-based access control across owner, administrator, compliance manager, compliance reviewer, auditor, case manager and adviser roles.
- Customer: enrol MFA in-app under Account → Security.
Audit trail
- Every privileged action is written to an append-only audit log.
- Audit records are chained with SHA-256 hashes so tampering can be detected.
- Records are protected by database-level write-once controls (WORM) and cannot be modified or deleted from the application layer.
Data model integrity
- Row-level security is enabled on every user-facing table.
- Cross-organisation data access is blocked at the database layer, not just in the application.
- Case reviews are backed by immutable snapshots — the exact state of a case at the point of review can be reproduced later.
- Legal holds block soft-delete and retention purges on affected records; release requires justification.
Data residency
- Application data is hosted in the United Kingdom / European Economic Area.
- No customer data is transferred outside the UK/EEA for primary storage.
- Sub-processors used for email, AI processing, or observability are listed in our Privacy Policy.
Backups & disaster recovery
- Point-in-time recovery (PITR) is enabled at the database layer.
- Retention window and RPO/RTO targets are documented in our internal disaster recovery record.
- Recovery rehearsals are performed on a documented schedule; findings and corrective actions are tracked.
Vulnerability management
- Automated security scans run on every deployment and are triaged before release.
- Report a suspected vulnerability to security@mortivoaudit.co.uk. Please do not test on production data.
Compliance roadmap
Mortevo Audit is currently in a controlled release for early customers. We are progressing toward a formal information security certification and will publish the certification body and scope on this page once achieved. We do not claim SOC 2, ISO 27001, or other certifications until independently verified.
Contact
Security queries: security@mortivoaudit.co.uk
Data protection: privacy@mortivoaudit.co.uk