Skip to content
motifuse

Motifuse Trust Centre

Trust Centre

Everything Motifuse publishes about how it works: the security model, what happens to your data, the standards behind the tools, and the legal agreements — each with the date it was last checked against the code.

Documents published
17
Operator
Motifuse Solutions, Kerala, India
Most recent review
Security contact
security@motifuse.com

How these documents are written

What you can expect from this index

Four rules the published documents are held to. They are the reason the pages read the way they do.

  • Describe what is built, not what is planned

    Every published control corresponds to code in the running product. Where something is not implemented, or is implemented for one product and not another, the document says so rather than staying quiet.

  • State the absences too

    Certifications, audits, guarantees and response times are listed by their absence when they do not exist. A page that lists only strengths is marketing, and a reader evaluating the platform cannot use it.

  • Keep one source for shared facts

    Retention periods, cookies, processors and processing boundaries are defined once and read by every page that mentions them, so two policies cannot quietly disagree about the same fact.

  • Date every review

    Each document carries the date it was last checked against the implementation, and that date moves only when the substance changes. Reformatting is not a review.

No small print

What Motifuse does not claim

The absences that matter most when you are deciding whether to trust a platform with real work. The full list, with the reasoning for each, is on the Security page.

See all 10
  • No certifications

    Motifuse is not ISO 27001 certified, not SOC 2 audited and not PCI DSS certified in its own right — card data is handled by Razorpay precisely so that it does not need to be.

  • No compliance attestation

    This is not a HIPAA-covered service, and no GDPR certification is claimed — no formal scheme of that kind exists in any case.

  • No independent security testing

    No third-party penetration test has been commissioned. Security work so far is design review, code-level controls, and fixing what gets reported.

  • No uptime or service-level guarantee

    There is no uptime commitment and no service-level agreement on any self-service plan, and no status page reporting one.

  • No response-time commitment

    Neither support nor security reports carry a published response window. Reports are read and acted on; a number that has not been measured will not be published.

  • No bug-bounty programme

    Good-faith reports are welcome and prioritised, but there is no reward scheme and none is implied.

Found something that looks wrong?

A security issue, a policy that contradicts the product, or a claim that does not match what you observed — all three are worth telling us about, and the second two get the document corrected.