Legal & Compliance
Security Policy
The administrative, technical, and organizational safeguards MumuWorks uses to protect customer data and service availability.
1. Security posture
MumuWorks implements reasonable administrative, technical, and organizational safeguards designed to protect customer data, preserve service integrity, and reduce the likelihood of unauthorized access, loss, misuse, alteration, or disclosure.
2. Encryption
MumuWorks uses encryption in transit for supported browser and API traffic. We also use encryption and access restrictions where appropriate for stored data, backups, credentials, and connected service secrets. The exact controls may vary by deployment environment and provider capability.
3. Access controls
Administrative access is limited to authorized personnel with a business need. We use account controls, authentication measures, role-based access, and operational review practices intended to support least-privilege access.
4. Logging, monitoring, and response
We maintain logs and operational monitoring to support troubleshooting, abuse detection, and incident investigation. Where a security event is confirmed to affect customer data, MumuWorks follows internal response procedures to contain, assess, remediate, and communicate the incident as appropriate.
5. Backup and continuity
MumuWorks maintains backup and recovery processes intended to support operational resilience and restoration after system failure or data-loss events. Backup frequency, retention, and restoration timing depend on deployment architecture, workload, and provider availability.
6. Shared responsibility
Customers also play a role in protecting their data by choosing strong credentials, limiting user access, configuring tenant permissions appropriately, securing connected third-party accounts, and reviewing AI and automation settings before production use.