Security and trust
How Mojo Up handles, protects and stores your data, and how to tell us about a security problem.
Mojo Up builds AI Workbench and its platform for organisations that have to answer for what their AI agents do. This section explains, in plain terms, what the platform holds, how it is protected, where it lives, and how you can check what happened.
Found a security problem?
Email security@mojoup.com.au. See Report a vulnerability.
In short
- Your agents work on your machines. They run on your workbenches and nodes, and talk to the AI providers you choose directly. The platform coordinates them; it does not run your models or hold your code.
- No passwords, and no tokens kept in the clear. People sign in through an identity provider. Every token the platform issues is random and stored only as a one-way hash.
- Secrets are encrypted. API keys your agents need are encrypted with AES-256-GCM and released only to signed-in machines.
- Remote control needs no open ports. Workbenches dial out to the relay, and every request they receive is signed by the platform and limited to the scopes they were approved with.
- Mojo Up AI Cloud is in Australia. It runs in Microsoft Azure's Australia East region. Self-hosted AIOE runs wherever you put it.
- What happened is on record. Every approval, enrolment, policy change and agent action reported to the platform is written to an append-only, hash-chained audit trail you can check.
Data handlingWhat the platform keeps, what it does not, and how long.Encryption and keysIn transit, at rest, tokens, secrets and signatures.Where data livesMojo Up AI Cloud's region and services, and self-hosted options.The audit trailAn append-only, hash-chained record you can verify yourself.Report a vulnerabilityHow to tell us, and what to expect.