Security & Accessibility

Open to everyone. Accountable to everyone.

A policy has to be readable by everyone it applies to and defensible in every audit. MOSI is built for both, from the first keystroke to the last export.

Accessibility

Accessibility isn’t a setting.

MOSI is designed and tested against Section 508 and WCAG 2.1 AA. That covers the portal your public or employees read, the hub your staff work in, and the admin screens that configure both.

  • Keyboard first

    Skip links, logical focus order, visible focus states, and menus that work without a mouse, across the staff hub, admin portal, and public portal.

  • Screen-reader ready

    Semantic headings and landmarks, labelled controls, and status messages that assistive technology can announce.

  • Contrast you can’t break

    The theme editor checks every brand color against WCAG AA and adjusts buttons automatically, so branding never costs accessibility.

  • Checks while you write

    An accessibility checker in the editor helps authors catch issues like missing alt text or skipped headings before a document is published.

  • Tested continuously

    Automated accessibility testing runs against the product’s pages, alongside manual review against Section 508 and WCAG 2.1 AA.

  • Accessible after publishing

    Published documents keep their heading structure, include glossary definitions on focus as well as hover, and print cleanly to PDF.

Security

Controls your security team will recognize.

Identity, access, encryption, and auditability are part of the platform, not a premium add-on.

  • Single sign-on

    Connect your identity provider over SAML or OIDC. New users are provisioned just in time into the right agency with read-only access.

  • Role-based access

    System roles for admins, authors, reviewers, and readers, plus custom roles built from granular permissions. Roles can cascade to child agencies.

  • Visibility per document

    Publish to the public, to signed-in staff only, or restrict a document to a single agency. Search respects the same rules.

  • Encryption

    Data is encrypted in transit and at rest. Secrets are held in a managed secret store, never in code.

  • Separated storage

    Each organization’s attachments and knowledge base files are kept in their own storage, apart from every other tenant.

  • Immutable audit events

    Every action is recorded with the user, resource, time, IP address, and user agent, in an audit store that is append-only.

Records

Nothing disappears. Everything exports.

Archiving is reversible, removed comments are retained, and every version is kept. When a records request arrives, you can hand over the full history with proof it hasn’t been altered.

  • Archive and restore, never hard delete
  • Every version kept, with who and when
  • One-click open records package
  • SHA-256 manifest for every file

FAQ

Security questions, answered.

Something else on your mind? Ask our team.

Is MOSI Section 508 and WCAG 2.1 AA conformant?

MOSI is designed and tested against Section 508 and WCAG 2.1 AA, and accessibility work is part of every release. We are happy to walk your accessibility coordinator through our current conformance and testing approach.

Can MOSI support our CJIS, HIPAA, or StateRAMP obligations?

MOSI provides controls those frameworks expect, including role-based access, single sign-on, encryption, audit logging, and data separation. Requirements differ by organization, so we review your specific obligations with your security team during evaluation.

Is anything ever permanently deleted?

Archiving and deleting in MOSI are soft operations. Archived documents can be restored, removed comments are retained for the record, and an open records export can include them.

How do we respond to an open records request?

An administrator selects the document, adds the request reference, and chooses what to include: versions as PDFs, comments, approvals, attachments, and changes between versions. MOSI packages it as a ZIP with a manifest of SHA-256 hashes and records the export itself in the audit trail.

Who at MOSI can access our data?

Administrative access to production systems is limited to authorized staff, gated by identity, and logged. Your organization controls who can see what inside MOSI through roles and document visibility.

Get started

Bring your security questionnaire.

We will walk your security and accessibility teams through the architecture, the controls, and how MOSI fits your obligations.