This page describes ModuleX’s compliance posture. It is a summary, not a legal document. The binding terms are the published Terms of Service and Privacy Policy. Where the two differ, the published legal documents govern.
Certifications: confirm the current status
ModuleX does not publish a list of completed third-party security certifications in these docs. Treat every certification below as not yet confirmed here until ModuleX gives you its current status in writing.SOC 2
Status not confirmed in these docs. TBD — contact sales for the current report or attestation status.
ISO 27001
Status not confirmed in these docs. TBD — contact sales.
HIPAA
ModuleX is not designed for regulated regimes (see below). TBD — contact sales before any healthcare use.
Other frameworks
For any other standard or questionnaire, contact sales for the current position.
Regulated industries: read this first
ModuleX’s Terms of Service state plainly that the service is not designed for use under regulated regimes such as HIPAA, GLBA, and PCI-DSS, unless ModuleX agrees to it in writing. This is a posture, not a gap to work around. If you handle protected health information, regulated financial data, or cardholder data, start the conversation early so the right agreement is in place first.Privacy laws ModuleX works under
ModuleX is operated by ModulexAI, LLC, which acts as the data controller for your account data under the GDPR. The privacy program is built around two major frameworks plus a range of US state laws.GDPR
For the EEA, UK, and Switzerland. ModuleX honors the data-subject rights below and relies on the European Commission’s Standard Contractual Clauses for cross-border transfers.
CCPA / CPRA
For California residents: the right to know, delete, correct, and opt out of the sale or sharing of personal information.
Other US state laws
Residents of many other US states (including Virginia, Colorado, Connecticut, Utah, and Texas) have similar rights under their own privacy laws.
PCI-DSS (payments)
ModuleX does not store your payment card details. Card data goes directly to the payment processor, which adheres to PCI-DSS.
Your privacy rights
If you are in the EEA, UK, or Switzerland, you can exercise the following rights over the personal information ModuleX holds. ModuleX may ask you to verify your identity first.Access, update, delete
See, correct, or remove the information ModuleX holds about you.
Rectification
Have inaccurate or incomplete information corrected.
Object
Object to ModuleX processing your personal information.
Restriction
Ask ModuleX to limit how it processes your information.
Data portability
Receive your data in a structured, machine-readable, commonly used format.
Withdraw consent
Withdraw consent where processing relied on it.
privacy@modulex.dev. You also have the right to complain to your local data protection authority.
How your data is handled
A few principles sit at the center of ModuleX’s data handling. Each links to the page with the full mechanics.Encrypted in transit and at rest
Data is encrypted in transit over TLS/HTTPS and at rest (AES-256 where applicable). Connected-service credentials are encrypted before they are stored.
Your work stays in your organization
Every resource belongs to exactly one organization, and ModuleX checks your membership on each request. One organization’s data does not reach another.
Not used to train AI models
Your prompts, workflow content, and connected-service data are not used to train AI models. AI processing is real-time and ephemeral; nothing is kept for training.
Access controls and monitoring
Role-based access with least privilege, multi-factor authentication for employee accounts, and security event monitoring and logging.
What happens to data sent to AI providers?
What happens to data sent to AI providers?
When you use ModuleX-managed models, your content is processed by AI providers (such as OpenAI, Anthropic, and Google Gemini) only to run your workflow, and is not used to train their models under their published API customer commitments. When you bring your own key, your data goes directly to that provider under your own account and terms. ModuleX does not use customer content to train any model, its own or a third party’s.
What about data from connected services like Google or Microsoft?
What about data from connected services like Google or Microsoft?
Data ModuleX receives from a connected service is used only to deliver the workflow features you ask for. For Google data, ModuleX affirms it follows the Google API Services User Data Policy, including the Limited Use requirements: no advertising use, no sale, no use for training generalized AI/ML models. The same Limited Use commitments apply to other connected services, including Microsoft Graph, Meta, and LinkedIn data. See Credentials & OAuth2 for how these connections are stored and scoped.
How long ModuleX keeps data
ModuleX states that it keeps data only as long as needed for the purpose it was collected for. The published retention windows are:
When you revoke access, delete your account, or stop using a feature, ModuleX removes the associated data within these windows. You can request deletion through in-app settings or by emailing
privacy@modulex.dev.
ModuleX also keeps an internal audit-log retention policy of 365 days for its own operational records. This is separate from the customer-facing retention windows above. Detailed self-hosted logging and retention controls are documented for engineers in Data security & encryption.
Where your data is processed
ModuleX processes data in the United States. If you are outside the US and provide information, it is transferred to and processed in the United States, where data-protection laws may differ from those in your own jurisdiction. For transfers from the EEA, UK, or Switzerland, ModuleX relies on the Standard Contractual Clauses approved by the European Commission.Reporting a security issue
ModuleX runs a vulnerability disclosure policy covering themodulex.dev website, the ModuleX web application, and the ModuleX API services. Email security reports to security@modulex.dev; ModuleX acknowledges receipt within three business days, and reports can be submitted anonymously.
If you become a customer and need a security or compliance review, that same address is the place to request the current status of any certification, report, or questionnaire.
Get the current status
Because certifications change over time, this page does not assert any of them. Get the current position directly before you rely on it.Talk to sales
For certification status, data-residency options, a data processing agreement, or regulated-industry use, contact the ModuleX team.
Email security
Reach the security team at
security@modulex.dev for security reviews, questionnaires, and vulnerability reports.Related pages
Trust & compliance
How ModuleX handles, retains, and protects data, in context.
Sub-processors
The third parties that may process data on ModuleX’s behalf.
Security overview
How the product is built to protect your data, credentials, and access.