blueForge docs

Trust center

MOBLUEHQ builds verification software for regulated workflows. This page is the public trust summary for procurement and InfoSec reviewers. Deep legal artifacts (pilot agreements, questionnaire exports) are shared during active sales conversations — not published here.

System status

Live service health and customer-visible incidents:

MOBLUEHQ status page →

For beta expectations and known limits, see Beta and known issues.


Security contact

ChannelDetail
Emailsecurity@mobluehq.com
ScopeVulnerabilities in MOBLUEHQ-operated services, product security questions, coordinated disclosure
ResponseAcknowledgment within 5 business days; critical issues prioritized

Do not paste exploits, PHI, or live credentials in public bug reports. Use the security contact or in-product Report with redacted logs. See Report bugs.


Vulnerability disclosure {#vulnerability-disclosure}

We support coordinated disclosure:

  1. Report to security@mobluehq.com with reproduction steps and impact assessment.
  2. Allow reasonable time to remediate before public disclosure (typically 90 days, shorter for active exploitation).
  3. We will confirm receipt, keep you informed of status, and credit researchers in release notes when desired.

We do not pursue legal action against good-faith research that respects customer data and avoids service disruption.


Subprocessors {#subprocessors}

MOBLUEHQ uses the following categories of subprocessors to operate our infrastructure (not your model inference, which uses your provider keys):

SubprocessorPurposeLocation
CloudflareDocs hosting, CDN, Pages deployUS / global edge
GitHubSource control, CI artifactsUS
Email provider (transactional)Support and onboarding emailUS

Model providers (Anthropic, OpenAI, Google, others) are invoked directly by your deployment with credentials you configure. They are your subprocessors under your agreements when you enable cloud models. MOBLUEHQ does not route prompts through a shared multi-tenant inference pool in standard editions.

For a DPA or updated subprocessor notification, contact your MOBLUEHQ onboarding channel.


Data handling summary

TopicSummary
ArchitectureCustomer content runs on-device, in your VPC, or in a dedicated demo environment — not in a MOBLUEHQ multi-tenant case database
What we may seeLicense checks (license ID, device ID, edition), support tickets you submit, aggregated status — not routine access to case content
ReceiptsCryptographically signed records of verification runs; you control export and retention
TrainingWe do not train on customer prompts or clinical content
HIPAABAA required before PHI; pilots use synthetic or de-identified data only until BAA is executed
SOC 2Type I in progress — not yet available for distribution

Full detail: Offline and privacy · Licensing · Verification


Compliance artifacts

ArtifactAvailability
Public trust summaryThis page
Security questionnaire answersOn request during procurement
SOC 2 reportNot yet issued — notify list via security contact
BAA / DPACounsel-reviewed versions on request
Penetration test summaryUnder NDA after completion