Security & Trust

You're about to connect your
whole estate to us. Here's the deal.

Modus reads from the systems that run your business — Microsoft 365, your device manager, your network, your help desk. That only works if you trust how we hold it. This page is the straight version: what we protect, how, who can see what, and where we're still early. No security theatre.

We're an early-stage, Australian, independent product. We are engineered against recognised controls, but we are not yet SOC 2 or ISO 27001 certified — those audits are a planned step, not a claim we'll make before it's true. Everything below describes what is actually built and running today.

What Modus can — and can't — reach

Two very different things are often confused. Here's the boundary, drawn honestly.

The free posture scan public data only

Run before you sign up, with no login. It looks only at what is already public about your domain — DNS records, TLS certificate configuration, published email-security records (SPF/DKIM/DMARC/MTA-STS), and HTTP security headers.

It never touches anything inside your network. To generate your report we keep your email, domain and the resulting score/band so we can send it to you and follow up. We do not store the individual findings, your IP, or any credential — there are none to store.

Connected integrations you authorise each one

Inside the app, Modus only reaches a system after you connect it and grant it access — through Microsoft's own consent screen, or by pasting an API key you control. You choose which systems, and you can disconnect any of them.

Modus reads configuration and inventory: directories, devices, licences, network config, tickets, posture signals. It is a read-and-reconcile platform, not a remote-control tool — it does not push changes back into your production systems.

How your keys and data are held

Integration credentials

The API keys and tokens you connect are encrypted with per-organisation AES-256-GCM envelope encryption — each organisation's secrets are sealed under their own data key, not one shared master key. They're decrypted only in memory, only to run the sync you asked for.

They are never written to logs, never shown back to you in full, and never sent to any AI model — the pipeline structurally excludes secrets before anything leaves the app.

Tenant isolation, at the database

Every organisation's data is separated by PostgreSQL row-level security, enforced in the database itself — not just by application code that could be bypassed by a bug.

  • Policies are fail-closed: no matching rule means no rows, not all rows.
  • The app connects as a role that cannot bypass row-level security.
  • Coverage is checked in CI — a table without a policy fails the build.

Where your data lives

Modus runs on managed cloud infrastructure. We're specific about it because vague "bank-grade cloud" claims help no one.

ProviderRoleRegion
Supabase (Postgres)Primary database & authenticationSingapore (ap-southeast-1)
VercelApplication hostingUnited States
Cloudflare R2Encrypted database backupsGlobal object storage
AnthropicAI-assisted featuresUnited States
InngestBackground job orchestrationUnited States
CloudflareWebsite, DNS & network securityGlobal network

Honest note on data residency. Your primary data is hosted in Singapore, and some processing (app hosting, AI, jobs) happens in the United States. We are Australian-owned and operated, but we do not currently guarantee Australian-only data residency. If sovereign hosting is a hard requirement for you, tell us before you commit — we'd rather say so up front. Cross-border handling is disclosed under APP 8 in our Privacy Policy.

Can Modus staff see my data?

Support access is possible, gated, and logged

To be straight with you: because we run the platform, a small number of authorised staff can access an organisation's workspace to provide support — this is true of essentially every SaaS you use. What matters is the controls around it, and here they are real:

  • Staff impersonation is role-gated — only a platform administrator can initiate it.
  • It requires a stated reason, and the session is fully audit-logged.
  • Every sensitive change in the platform is written to an append-only audit trail you can be shown.

We do not sell your data, we do not use it for advertising, and we do not mine it across customers.

How AI features use your data

What goes to the AI, and what never does

Modus's assistant, diagram generation and compliance drafting are powered by Anthropic's commercial API. To answer questions about your estate, relevant records — directory, device, ticket and posture data — are sent to that API. Under Anthropic's commercial terms, this data is not used to train models.

  • Secrets are structurally excluded — your integration credentials are never included in any AI request.
  • AI output is presented for human review, never executed automatically against your systems.

Being straight about the roadmap: a formal data-processing agreement with Anthropic and a per-organisation toggle to disable AI features entirely are on our list, not yet shipped. If AI-off is a requirement for you today, tell us and we'll work with you.

Our own compliance posture

We build compliance tooling, so we hold ourselves to the same honesty we'd want from a vendor.

Engineered against

  • The ACSC Essential Eight — the model we build the product around
  • The Privacy Act 1988 & Australian Privacy Principles
  • The Notifiable Data Breaches scheme
  • ASD ISM controls — mapped and aligned as a reference

Not yet certified planned

We are not currently SOC 2 Type II or ISO 27001 certified, and we won't imply otherwise. Formal certification is a deliberate later step once the controls have a longer operating history.

What you get today is a product built by people who do this for a living, with the controls described on this page actually in place — and a vendor who will tell you plainly what isn't done yet.

Accounts, backups & continuity

Signing in

Sign in with your Microsoft (Entra) account so your own MFA and conditional-access policies apply to Modus — the strongest option, and the one we recommend.

Email-and-password sign-in is also available. Native app-level MFA for password accounts is a known gap we're closing — for now, prefer Microsoft sign-in.

Backups & your data

The database is backed up to encrypted Cloudflare R2 storage. Your data is yours — you can export your organisation's records, and on verified request after you close your account, we delete them.

Vendor continuity

Modus is a small, independent company. We're not going to pretend otherwise. Your protection is practical: your data is exportable at any time, so you are never locked in, and a wind-down would come with an export window — not a locked door.

If something goes wrong

We comply with the Notifiable Data Breaches scheme. If a breach is likely to cause serious harm, we notify affected organisations and the OAIC as the law requires — see the Privacy Policy.

Found a security issue?

We want to hear it. Email security@modusmsp.com — our published security.txt has the details. We'll acknowledge and work the issue with you in good faith.

We eat our own cooking

The same free posture scan we offer you, we run on our own domains. Check us the way you'd check any vendor — run the scan on modusconverge.com and see the score for yourself.

Trust, then connect

See exactly what we'd see.

Start with the free external scan — no login, no card, public data only. If you like what you see, connect your first system and watch the graph build.