Match the control to the information and the consequence.

This public overview describes Mojoflow’s intended security posture without exposing operational security details. Engagement-specific controls are established during contracting and discovery.

Data minimization

Initial enquiries should contain only the minimum information required to assess fit. Sensitive client information is handled through agreed channels, access controls, and retention expectations.

Third parties

Hosting, booking, collaboration, analytics, AI, and delivery vendors are evaluated according to the information and risk involved. Vendor use is disclosed or agreed where the engagement requires it.

Access and delivery

Engagement access should follow least privilege, named ownership, appropriate authentication, controlled sharing, and timely removal when no longer required.

Reporting

Potential security concerns related to the website may be sent to security@mojoflow.ca. Do not include exploit code, credentials, personal information, or client-confidential material in an initial report.