Skip to content
Contact us

Security

Security you can put in front of an auditor.

How we build and run Moatgator so that your security review can say yes.

  • Ephemeral builds

    Build artifacts are short-lived and expire after 24 hours, and each build runs in an isolated worker.

  • Your signing keys stay yours

    Signing happens in your pipeline. Moatgator never holds your signing keys, certificates or provisioning profiles.

  • Least-privilege access

    The GitHub App asks only for the permissions it needs, and the GitHub Action authenticates with OIDC instead of long-lived secrets.

  • Aligned with OWASP MASVS

    Scan reports map findings to MASVS controls your auditors already know.

  • Telemetry that respects users

    Pulse collects security signals about devices and attempts, not your users' content, with sampling, retention by plan and a choice of region.

  • LGPD-ready

    We handle personal data under the LGPD. Data processing terms and the subprocessor list are available on request.

  • Secure development

    Our own pipeline runs static analysis, dependency checks and secret scanning on every change.

  • Access to our systems

    Production access requires MFA and single sign-on with approval, and sensitive internal actions leave an audit trail.

Documents available on request

  • Data processing terms
  • Subprocessor list
  • Security questionnaire answers
  • MASVS-mapped sample report

Security questions

Do you store my app's source code?

No. Protection runs on the compiled app in your pipeline, and build artifacts expire after 24 hours.

Who holds the signing keys?

You do. Moatgator returns an unsigned artifact and your pipeline signs it.

What personal data do you process?

Only what you send through our forms, and security signals about devices and attempts through Pulse, never your users' content.

Can you answer our security questionnaire?

Yes. Contact us with your questionnaire or review requirements.

Does protection make an app impossible to attack?

No. Protection raises the cost of attacks and makes them visible. It reduces risk; it does not eliminate it.

Need security documentation?

Tell us what your review requires and we will send it.