Company access is scoped, authenticated, and controlled.
Morrow is designed to limit company information to authorized users through authenticated access, company-scoped membership, and server-authoritative permission checks. This page describes current, app-visible controls. No method of transmission or storage is completely secure; Morrow applies reasonable safeguards appropriate to the nature of the service and information processed. Morrow does not currently claim independent SOC 2, ISO 27001, HIPAA, PCI, or similar certification.
Access requires an authenticated account. Sign-in is available through Google and email, with email verification. Sessions and credentials are managed through Morrow's authentication layer.
Company membership determines which workspaces a user can see. Role and permission checks — owner, admin, member, viewer, and other roles where applicable — are enforced server-side, not in the browser.
Company records are isolated by workspace. Row-level access policies are applied so that authorized members see only their own company's data.
Traffic between the browser and Morrow is protected in transit using industry-standard TLS. Encryption at rest is provided by the underlying database and storage infrastructure and is subject to change as providers change.
Company invitations, shared Decision Memo links, and referral links use opaque tokens. Invitations and share links can expire and can be revoked by an authorized member.
Consequential actions — approvals, decisions, membership changes, and billing transitions — are captured in the company's audit history so that authorized members can review who did what.
Public entry points such as the contact form, feedback, affiliate applications, and shared links have reasonable rate-limit and abuse controls. Specific thresholds are not published so they remain effective.
Provider API keys, model-gateway credentials, and payment secrets are stored server-side and are not exposed to browsers.
Database and storage backups are provided by the underlying platform. Morrow does not publish specific backup frequency or recovery time objectives; those are subject to the platform provider and may change.
Morrow tracks and updates third-party dependencies over time. Security-relevant updates are applied on an ongoing basis; Morrow does not publish specific patch SLAs.
When a member is removed from a company, their access to that company's workspace ends. When an account is deleted, remaining access is revoked subject to operational and legal retention constraints.
If Morrow becomes aware of a security incident that is reasonably likely to have affected customer information, Morrow will investigate and communicate with affected customers where required. Morrow does not publish a specific incident-notification timeline commitment on this page; where a contract sets a specific timeline, that contract controls.
Report a security or vulnerability concern to support@meetmorrow.ai. Include reproduction detail and impact where possible. Morrow does not currently operate a paid bug-bounty program.
- Last updated
- July 22, 2026
- Canonical URL
- https://meetmorrow.ai/security