Menu

Access controls and operational limits

Understand the account, publication, file and provider boundaries before putting client information into Moolamochi.

Use verified accounts and narrow grants

Accounts use email verification, revocable sessions and optional TOTP multi-factor authentication with recovery codes. Workspace roles, project assignments and client grants constrain access. A payment link grants only its allowed document actions; platform support staff do not gain general tenant access.

Files stay private and are checked before use

The file flow places uploads in quarantine for type, size and malware checks. Unavailable or failed scans keep files non-downloadable. Private downloads recheck current access; revocation prevents new downloads but cannot recall bytes someone already saved. Issued invoice snapshots retain the branding and document data they were issued with.

Know the boundaries of these controls

Provider availability depends on configured and authorized connections. A connected account or a clean file scan is not a guarantee against every threat. No independent audit, security certification, regulatory compliance certification or uninterrupted availability is claimed here. Staging is a test environment, and its release verification remains an operational gate.

Report a security concern privately

Use the support form to describe the affected feature and a safe way to contact you. Do not send passwords, API keys, payment card details or private document contents. Request a secure follow-up channel before sharing sensitive evidence.