MongoQUI is offline-first by default, cloud-enabled on your terms, and built on a controls list we implement: Argon2id master passwords, TOTP, per-device sessions, AES-256 for shared credentials, and an org-wide audit log.
- Transport
- TLS
- At rest
- AES-256
- Master password
- Argon2id hash
- SOC 2
- Audit in progress
Twelve controls.
Every one maps to shipping code.
These are not aspirational. Every entry below corresponds to an auth, encryption or logging path already in production across the desktop app, the cloud control plane and the serverless analytics layer.
Argon2id master password
Locks the desktop app. Saved connection credentials are encrypted at rest on your machine, never stored in plaintext.
Org-scoped API requests
Every API call carries a signed JWT, and the gateway checks the requested organisation against your membership, so cross-org requests fail at the gateway.
TOTP two-factor auth
Backed by otplib in the auth service. Enrolment and recovery handled inside the app.
Bot check on sign-in
A Cloudflare Turnstile challenge guards sign-up and sign-in against automated abuse.
Rate limiting
Rate limits on sign-in and account routes, AI generation and report suggestions keep brute force and runaway automation in check.
AES-256-GCM shared credentials
Shared-connection credentials are encrypted at rest in the control plane with a 256-bit key held outside the database. Team members never see the raw secret.
TLS in transit
Traffic is encrypted with TLS from the app to our edge and from the edge to the analytics layer.
Internal service auth
Service-to-service calls carry a shared secret header (X-Internal-Secret). A leaked user token cannot impersonate the gateway.
Audit log
Account and team events are recorded with actor and timestamp: invites and removals, role and seat changes, 2FA changes and shared-connection edits.
Password-protected share links
Salted PBKDF2-SHA256 password hashes and an optional expiry timestamp. The report owner can turn a link off at any time.
Action-level gating
Share-link edit actions (AI suggestions, data refresh) need edit permission plus a password unlock or signed-in session. Only the report owner can delete a report.
CORS allow-list
Explicit origin allow-list on every authenticated API. Only public blog images use a wildcard origin.
Designed for GDPR · Data subject access, export and deletion endpoints exist; DPO requests are routed to privacy@mongoqui.com. A public trust portal is planned, expected alongside the SOC 2 close.
Local by default.
Cloud on request.
The exact language we want
quoted in your RFP.
We do not claim certifications we do not hold. Where we have controls but no audit, we say so. Where we are not the right vendor, we say that too.
Every third party
that touches data.
For the DPA readers. Each vendor below processes customer data for a specific purpose and only when the feature they power is in use.
Found something?
Tell us.
Report anything you find, no matter how small, to the address on the right. We operate a 90-day coordinated disclosure window, acknowledge within two business days, and publish a credit on the changelog with your permission once the fix ships.
No active bug bounty programme yet. We offer swag and public credit today and will announce a bounty when we can do it properly. Please do not run disclosure research against app.mongoqui.com or api.mongoqui.com with real customer data. Contact us first so we can spin up an isolated test org.
Answers for
security reviewers.
For a full controls deep-dive or a signed questionnaire, email security@mongoqui.com.
Procurement calling?
Talk to security.
Request a DPA, the current SOC 2 status letter, or a call with the engineers who built the controls above. Real people, real answers. No sales middleware.