SECURITY

Company access is scoped, authenticated, and controlled.

Morrow is designed to limit company information to authorized users through authenticated access, company-scoped membership, and server-authoritative permission checks. This page describes current, app-visible controls. No method of transmission or storage is completely secure; Morrow applies reasonable safeguards appropriate to the nature of the service and information processed. Morrow does not currently claim independent SOC 2, ISO 27001, HIPAA, PCI, or similar certification.

Authentication
Verified access to every workspace.

Access requires an authenticated account. Sign-in is available through Google and email, with email verification. Sessions and credentials are managed through Morrow's authentication layer.

Company membership and roles
Access is scoped per company.

Company membership determines which workspaces a user can see. Role and permission checks — owner, admin, member, viewer, and other roles where applicable — are enforced server-side, not in the browser.

Tenant isolation
Company records stay isolated.

Company records are isolated by workspace. Row-level access policies are applied so that authorized members see only their own company's data.

Encryption in transit
TLS between clients and Morrow.

Traffic between the browser and Morrow is protected in transit using industry-standard TLS. Encryption at rest is provided by the underlying database and storage infrastructure and is subject to change as providers change.

Tokens and shared links
Opaque tokens with expiration and revocation.

Company invitations, shared Decision Memo links, and referral links use opaque tokens. Invitations and share links can expire and can be revoked by an authorized member.

Audit history
Consequential actions are recorded.

Consequential actions — approvals, decisions, membership changes, and billing transitions — are captured in the company's audit history so that authorized members can review who did what.

Rate limits and abuse controls
Reasonable limits protect the service.

Public entry points such as the contact form, feedback, affiliate applications, and shared links have reasonable rate-limit and abuse controls. Specific thresholds are not published so they remain effective.

Provider secrets
Secrets are kept server-side.

Provider API keys, model-gateway credentials, and payment secrets are stored server-side and are not exposed to browsers.

Backups and continuity
Managed by the underlying platform.

Database and storage backups are provided by the underlying platform. Morrow does not publish specific backup frequency or recovery time objectives; those are subject to the platform provider and may change.

Dependencies and updates
Ongoing dependency maintenance.

Morrow tracks and updates third-party dependencies over time. Security-relevant updates are applied on an ongoing basis; Morrow does not publish specific patch SLAs.

Access removal
Removing a member ends their access.

When a member is removed from a company, their access to that company's workspace ends. When an account is deleted, remaining access is revoked subject to operational and legal retention constraints.

Incident response
Morrow investigates and communicates.

If Morrow becomes aware of a security incident that is reasonably likely to have affected customer information, Morrow will investigate and communicate with affected customers where required. Morrow does not publish a specific incident-notification timeline commitment on this page; where a contract sets a specific timeline, that contract controls.

Reporting a concern
Security contact.

Report a security or vulnerability concern to support@meetmorrow.ai. Include reproduction detail and impact where possible. Morrow does not currently operate a paid bug-bounty program.

Page details
Version
Last updated
July 22, 2026
Canonical URL
https://meetmorrow.ai/security