Security


Our Approach

Motum is designed around a simple principle: we process only the data required to deliver the Services, we keep it protected, and we never use our customers' data for our own purposes. Where we process data on a customer's behalf — including data about their clients and members — we do so only on that customer's instructions.


Infrastructure and Hosting

The Motum platform runs on enterprise-grade cloud infrastructure operated by established providers that maintain independent security certifications, including SOC 2 Type II:

We do not operate our own physical servers. Relying on audited infrastructure providers means the underlying data centers, network security, and physical controls are managed to recognized industry standards.


Encryption


Access Control and Authentication

Access to customer data is restricted to what is necessary to operate and support the Services:


Messaging and Communications Security

Messages sent through the Services are transmitted through Twilio, a compliant communications provider. Text messaging is consent-based: recipients must have opted in, and opt-out requests (replying STOP) are honored automatically. We do not share mobile numbers or messaging consent data with third parties for marketing purposes.


Data Handling and Minimization


Protecting Data About Minors

Some of the businesses we serve operate youth programs, which means the Services may process information about minors on the customer's behalf. We treat this data with heightened care: it is processed only on the customer's instructions, only to deliver the Services, and never used for any other purpose. The business customer remains responsible, as the controller, for obtaining any consents required by law, including under the Children's Online Privacy Protection Act (COPPA).


Subprocessors

We are transparent about the third-party providers that support the Services. Our primary subprocessors are:

Each subprocessor is bound by contractual obligations to protect the data they process on our behalf and to use it only to provide services to us. A current list is available to customers on request.


Incident Response

If we become aware of a security incident affecting customer data, we will investigate promptly and notify affected customers without undue delay, consistent with our contractual commitments and applicable law. We work with our infrastructure providers to contain and remediate incidents.


Shared Responsibility

Security is a partnership. Motum secures the platform and the infrastructure it runs on. Customers are responsible for safeguarding their own account credentials, managing who on their team has access, and ensuring they have the necessary consents for the data and contacts they bring into the Services.


Compliance Posture

Motum is built on infrastructure that maintains SOC 2 Type II compliance, and we align our internal practices with those standards. Motum has not yet completed an independent SOC 2 audit of its own; we will update this page as our formal compliance program matures. Customers with specific compliance requirements can contact us to discuss their needs.


Reporting a Vulnerability

If you believe you have found a security vulnerability in the Motum platform, please contact us at security@usemotum.com. We take all reports seriously and will respond promptly.


Contact