Security

Security by design for MongoDB teams.

MongoQUI is offline-first by default, cloud-enabled on your terms, and built on a controls list we implement: Argon2id master passwords, TOTP, per-device sessions, AES-256 for shared credentials, and an org-wide audit log.

Transport
TLS
At rest
AES-256
Master password
Argon2id hash
SOC 2
Audit in progress
SOC 2 Type II
Audit in progress · not certified
GDPR / UK GDPR
Designed to comply · DPA on request
ISO 27001
Not certified
HIPAA
Not supported · no BAA
Controls we implement today

Twelve controls.
Every one maps to shipping code.

These are not aspirational. Every entry below corresponds to an auth, encryption or logging path already in production across the desktop app, the cloud control plane and the serverless analytics layer.

Control 01

Argon2id master password

Locks the desktop app. Saved connection credentials are encrypted at rest on your machine, never stored in plaintext.

Control 02

Org-scoped API requests

Every API call carries a signed JWT, and the gateway checks the requested organisation against your membership, so cross-org requests fail at the gateway.

Control 03

TOTP two-factor auth

Backed by otplib in the auth service. Enrolment and recovery handled inside the app.

Control 04

Bot check on sign-in

A Cloudflare Turnstile challenge guards sign-up and sign-in against automated abuse.

Control 05

Rate limiting

Rate limits on sign-in and account routes, AI generation and report suggestions keep brute force and runaway automation in check.

Control 06

AES-256-GCM shared credentials

Shared-connection credentials are encrypted at rest in the control plane with a 256-bit key held outside the database. Team members never see the raw secret.

Control 07

TLS in transit

Traffic is encrypted with TLS from the app to our edge and from the edge to the analytics layer.

Control 08

Internal service auth

Service-to-service calls carry a shared secret header (X-Internal-Secret). A leaked user token cannot impersonate the gateway.

Control 09

Audit log

Account and team events are recorded with actor and timestamp: invites and removals, role and seat changes, 2FA changes and shared-connection edits.

Control 10

Password-protected share links

Salted PBKDF2-SHA256 password hashes and an optional expiry timestamp. The report owner can turn a link off at any time.

Control 11

Action-level gating

Share-link edit actions (AI suggestions, data refresh) need edit permission plus a password unlock or signed-in session. Only the report owner can delete a report.

Control 12

CORS allow-list

Explicit origin allow-list on every authenticated API. Only public blog images use a wildcard origin.

Designed for GDPR · Data subject access, export and deletion endpoints exist; DPO requests are routed to privacy@mongoqui.com. A public trust portal is planned, expected alongside the SOC 2 close.

Data flow · Where your data actually goes

Local by default.
Cloud on request.

Local-only lane
Personal connections · queries · imports · exports
3 hops
Desktop app
Tauri shell
Local backend
Python sidecar
Your MongoDB
Atlas or self-hosted
Opt-in cloud lane
Shared connections · AI · Report Builder · team admin
3 hops
Desktop app
JWT · org-scoped
API gateway
TLS · CORS
Analytics engine
SQL over Parquet
Compliance posture · Honest and current

The exact language we want
quoted in your RFP.

We do not claim certifications we do not hold. Where we have controls but no audit, we say so. Where we are not the right vendor, we say that too.

SOC 2 Type II
Audit in progress
Not certified. Contact security@mongoqui.com for the current status letter
GDPR
Designed to comply
No third-party attestation. See privacy policy · DPA on request
UK GDPR
Same as GDPR
Contact privacy@mongoqui.com
CCPA
Designed to comply
Rights honoured via privacy@mongoqui.com
HIPAA
Not supported
No BAA offered · do not process PHI
ISO 27001
Not certified
Framework informs the architecture. No audit, no certificate
Sub-processors

Every third party
that touches data.

For the DPA readers. Each vendor below processes customer data for a specific purpose and only when the feature they power is in use.

Cloud platform
CDN · edge compute · database · object storage · serverless functions · AI inference
EU · US
Analytics platform
Serverless analytics with in-memory SQL engine over Parquet data
US
Email service
Transactional email · sender noreply@cz.mongoqui.com
Global
Stripe
Subscription billing · invoicing · license.mongoqui.com
Global
OpenAI
AI query assistant · invoked only when the feature is used
United States
Google · GitHub (OAuth)
Optional social sign-in · only the identity handshake, only when you choose it
Global
Responsible disclosure

Found something?
Tell us.

Report anything you find, no matter how small, to the address on the right. We operate a 90-day coordinated disclosure window, acknowledge within two business days, and publish a credit on the changelog with your permission once the fix ships.

No active bug bounty programme yet. We offer swag and public credit today and will announce a bounty when we can do it properly. Please do not run disclosure research against app.mongoqui.com or api.mongoqui.com with real customer data. Contact us first so we can spin up an isolated test org.

Frequently asked · security

Answers for
security reviewers.

For a full controls deep-dive or a signed questionnaire, email security@mongoqui.com.

Your MongoDB data stays in your MongoDB deployment. MongoQUI metadata (org, users, seats, shared-connection ciphertext, Report Builder snapshots) sits in our cloud database and object storage with regional residency. Parquet snapshots for reports live in object storage; SQL aggregations run in serverless analytics.
Final CTA · /security

Procurement calling?
Talk to security.

Request a DPA, the current SOC 2 status letter, or a call with the engineers who built the controls above. Real people, real answers. No sales middleware.

Request a DPATalk to securitysecurity@mongoqui.com · 2-day ack SLA