Security
What Mochi Deploy stores about your Aprimo configuration, and how it's handled.
Mochi Deploy manages your Aprimo configuration, such as fields, content types, classifications, rules, and settings. To do that it stores the credentials you save for each environment and a record of your configuration changes. This page explains how that information is protected, in plain terms.
Encrypted in transit
Traffic between your browser and Mochi, and between Mochi and your Aprimo instance, travels over an encrypted connection.
Encrypted at rest
The data Mochi stores is encrypted while it sits in our database. The most sensitive items get an extra layer on top: the credentials you save for each environment, and sensitive values inside your configuration such as settings values and default values, are encrypted individually before they're written down.
Your organization has its own keys
Each organization gets its own set of encryption keys, rather than everything sharing one. Those keys are held by a dedicated key service, kept apart from the data they protect.
Keys can be replaced with fresh ones over time. That happens in the background, and anything written under an older key keeps working while it does, so there's nothing for you to do when it happens.
Your workspaces stay separate
Every request is checked against the workspace it's for, and against the access the person or program making it has been given in that workspace.
If you connect your own AI assistant
An admin chooses which workspaces and Aprimo instances an AI assistant can reach, and whether it can change anything or only look. Once you connect your own assistant, whatever it reads goes to that assistant and the company that provides it, and it's handled under your agreement with them rather than ours. Worth a look at their terms before you point one at a production instance. See Give an AI agent access.
When an organization is deleted
Deleting an organization cuts off access straight away. Memberships, access keys, and connected AI clients stop working at that moment.
The stored data itself sticks around for a short recovery period, currently 30 days, so a deletion made by mistake can still be put back. After that it's deleted, along with the organization's encryption keys.
Found a problem you think we should know about? See Reporting a security issue.
