Skip to Content
SecurityTrust Center

Trust Center

Security Overview

Controls: Security Whitepaper.


Compliance

StandardStatus
SOC 2 Type IIFollowing aligned practices; formal audit planned
ISO 27001Planned
Penetration testingThird-party testing planned
WCAG 2.2 Level AAAccessibility statement

How to verify AI marking

Look for:

  • PDF / Word document properties and footers containing AI-generated content · Motif and a motif-ai-provenance/1 unique id.
  • JSON exports: top-level or metadata provenance object with aiGenerated: true.
  • Excel: _motif_provenance sheet.
  • CSV: leading # motif-ai-provenance/1 … comment line.
  • GraphML: graph-level aiGenerated / motifMarking data keys.
  • Long assistant clipboard copies: [AI-generated by Motif] prefix.
  • Shared findings / copied association text: same clipboard prefix.

Data Residency

  • Stored data (database, object storage, cache, application hosting): United States
  • AI pipeline compute: Netcup VPS (may process query and document content outside the United States)
  • AI inference: Performed by third-party model providers via OpenRouter. Depending on routing, these providers may process query and document content outside the United States and EU.
  • Planned: EU stored-data options on roadmap

Subprocessors

ProviderPurposeLocationCertifications
VercelApplication hostingUSASOC 2
NetcupAI pipeline computeEUISO 27001
NeonPostgreSQL databaseUSA (AWS)SOC 2 Type II, ISO 27001
CloudflareObject storage for uploaded documents and session replay recordings (when session-replay consent is given); status-page subscriber emailsUSASOC 2, ISO 27001
UpstashRedis cache and job queueUSASOC 2
OpenRouterAI inference gateway (routes to third-party LLM providers)USA; routed providers may be outside US/EUPer routed provider
OpenAIModeration of profile and organization names (flagged names are rejected)USASOC 2
StripePaymentsUSAPCI DSS Level 1
ResendEmailUSASOC 2
SlackCommunity and personal support chatUSASOC 2

Other parties

These parties are not subprocessors. Google sign-in and reCAPTCHA run so Google can operate those services. Google Analytics and the Meta Pixel run only after consent, for their own analytics and advertising.

PartyPurposeLocation
GoogleAuthentication (OAuth), bot protection (reCAPTCHA), and analytics (when consented)USA
MetaAdvertising measurement (when marketing cookies are consented to)USA

LLM providers in the OpenRouter route: on request at hello@motif.bio.

We provide 30 days notice before adding a subprocessor that processes personal data. Subscribe: hello@motif.bio.


Incident Response

Security Whitepaper §6.


Responsible Disclosure

Email hello@motif.bio. We acknowledge reports within 48 hours, provide status updates, credit researchers if desired, and take no legal action for good-faith research.


Contact

PurposeEmail
Securityhello@motif.bio
Privacyhello@motif.bio
Legal/DPAData Processing Agreement; countersigned copy at hello@motif.bio
Supportsupport@motif.bio; Slack channels in Support & SLA
Last updated on