Security
Billing data is financial data. We treat it that way.
Morag holds your customers, your rate cards and your supplier costs. Here is how that is protected, and what we do not claim.
- Access control
- Role-based permissions with multi-factor authentication on privileged roles. Customers see only their own accounts through a separately authenticated portal.
- Tenant isolation
- Every query is scoped to the owning tenant, and customer-facing endpoints are constrained to the authenticated account rather than filtering in the browser.
- Auditability
- Billing runs are immutable. Charges, rate changes and invoice corrections keep a full history, so any figure can be traced to the record and the person behind it.
- Data handling
- Billing data is held in a managed Postgres instance in a London region, with encrypted transport throughout and scheduled backups.
- Least data
- We ask for the data needed to bill and reconcile, and nothing else. Files sent for a billing health check are used for that analysis and then deleted.
- Responsible disclosure
- If you believe you have found a vulnerability, email us and we will acknowledge it within one working day. We will not pursue anyone acting in good faith.
In progress
No certification claimed
Morag does not hold SOC 2 or ISO 27001, and we are not going to imply otherwise. If your procurement process needs a security questionnaire completed, send it over and we will answer it in full — including the parts where the answer is 'not yet'.
