This page describes how Moulds AI Inc., a Delaware C-Corp (“moulds.ai”) protects your data. It is governed by the laws of the State of Delaware.
We’ve tried to describe mechanisms you can check in the product rather than a posture you have to take on faith. Where we can’t point at something, we’ve left it out.
Data Protection
Data in transit between you and moulds.ai is encrypted using industry-standard TLS.
Access Controls
Access to your worker configurations and your data is restricted and logged. We use role-based access controls, and only authorised personnel have access.
You Approve What Goes Out
Any step that sends something outward gets an approval step in front of it — enforced by the platform, not by convention: a worker without the gate can't be saved, and the engine refuses to run an ungated send. That covers workers composed for you, hand-written ones, installed ones, and scheduled runs. The run stops there and waits for you to approve it before anything is sent.
Every AI Call Is On the Record
Each run keeps a per-call trace — the exact prompt sent and the response returned — alongside a plain-English list of the steps taken. You can see precisely what happened and why. Our Trust page shows this in the product.
Your Own AI Keys
You can bring your own AI keys. They’re held in the platform vault and used only for your runs.
Monitoring & Incident Response
We monitor our systems for security threats and have incident response procedures in place. In the event of a security incident affecting your data, we will notify you promptly and act to limit the impact.
Reporting Security Issues
If you find a vulnerability or have a concern about our security practices, report it to security@moulds.ai. We take every report seriously and will investigate promptly.