Security and Subprocessors

Direct answer

Controls are described with their configuration status rather than as blanket guarantees. Several are configured per customer instance rather than enforced identically everywhere, and that is stated where it applies.

Security overview

MorpheusOS is built to isolate customer environments and protect customer data. Controls in the product include:

  • dedicated customer instances;
  • regional deployment cells;
  • encryption in transit and at rest;
  • customer-specific credentials and keys;
  • role-based access controls and workspace-level permissions;
  • audit trails for administrative, agent, workflow and privacy-related events;
  • step-up verification for certain destructive or sensitive administrative actions;
  • credentials stored in encrypted form and not returned in full through normal administrative views;
  • configurable PII classification, redaction, audit and subject-request controls;
  • model-provider posture checks for sensitive data;
  • operational logging designed to strip credentials and sensitive-tier personal information; and
  • release checks designed to prevent cross-customer data access.

Several of these controls are configured per customer instance rather than enforced identically on every instance. Where a control depends on customer configuration, that is stated rather than implied.

What we do not claim

We do not currently claim SOC 2, ISO 27001, HIPAA or GDPR certification, and no statement on this site should be read as one. We describe controls, responsibilities and review requirements rather than compliance outcomes.

Subprocessors

These are the providers we use to deliver MorpheusOS. Each is bound by confidentiality and data-protection obligations appropriate to what it handles.

ProviderWhat it does for usWhat it can touch
Amazon Web ServicesCloud hosting, storage, compute, backup and content delivery for the platform and this website.Customer Data at rest and in transit, application state, backups and operational logs.
StripePayment processing and billing.Billing contact details and payment method data. No workspace content.
AnthropicModel inference for AI-assisted workflow steps.Prompt and workflow content sent for inference, which may include Customer Data.
OpenAIModel inference for AI-assisted workflow steps.Prompt and workflow content sent for inference, which may include Customer Data.
xAIModel inference for AI-assisted workflow steps.Prompt and workflow content sent for inference, which may include Customer Data.
GoogleModel inference for AI-assisted workflow steps.Prompt and workflow content sent for inference, which may include Customer Data.

Model providers are a special case

By default you supply your own model provider account or API key. Where you do, you contract with that provider directly, the provider is not processing on our behalf, and your agreement with them governs that use. See Model providers, tokens and usage costs.

The model providers above are listed because we may supply that access where it is expressly agreed in writing, and in that case they do process on our behalf. Which providers a workflow reaches depends on how it is configured.

Where processing happens

Customer instances are provisioned in supported regions, and Australia and the United States are currently available.

A subprocessor may process data outside your instance region. The processing locations that apply to your configuration are confirmed in your order form or on request.

Changes to this list

This list changes as the service changes, which is why it is published with a notice commitment rather than as a fixed set.

We will give at least 30 days’ notice before a new subprocessor begins processing Customer Data, by updating this page and notifying the contact on your account. You may object on reasonable data-protection grounds, and we will work with you to resolve it.

Reporting a security issue

Security issues can be reported to contact@morpheusos.ai.

For how isolation works and how it is verified, see Security & trust.