Security and trust
Mora touches your real client email. It is built to earn that.
You are connecting the inbox your business runs on. Here is exactly how Mora handles that responsibility, in plain terms.
Nothing sends without your approval
Mora drafts replies, nudges, and follow-ups, but it never sends them on its own. Every outbound action waits for your explicit approval.
It proposes, you decide
Suggested tasks, calendar items, and notes are proposals. Anything outbound or destructive requires a confirmation, and that confirmation is bound to exactly what you approved.
Your data is separated per user
Each account's data is isolated at the database layer, so one user's email, tasks, and clients are never visible to another.
Gmail tokens are encrypted
The access tokens that connect Mora to your Gmail are encrypted at rest with AES-256-GCM.
Your email is not training data
Your email content is not used to train third-party AI models. It is used to run your workspace, and that is all.
AI outputs are grounded in your data
Summaries, tasks, and answers are built from your actual email, tasks, and records, not invented. Anything Mora creates is marked and can be reviewed, edited, or removed.
What we don't claim
No badges we haven't earned
Security marketing is full of language that sounds reassuring and means nothing. We would rather be precise.
- We don’t claim certifications we don’t hold. You won’t see SOC 2, HIPAA, ISO 27001, or GDPR badges here unless we actually hold them.
- We don’t use vague phrases like “military-grade security.” We tell you the specific measure instead.
- During beta, self-serve data export and deletion controls are visible but handled manually. Email us and we take care of it.
- We don’t promise features that aren’t built. If something is planned, we say planned.
See what your business looks like when the inbox organizes itself.
Connect Gmail, give Mora a few minutes with your recent mail, then open Clients and Tasks. Request access and we'll set you up.
