MOON & STAR TERMINAL // SECURITY
MOON & STAR // TRUST CENTER

Clear boundaries around identity, payments, and data.

The platform is still in private beta, but the trust model is intentional: authenticated access, hosted payment handling, encrypted web delivery, separated private market infrastructure, explicit data-source labeling, and no custody or securities execution.

IDENTITY

Authenticated application access

Customer identity and sign-in are handled through the identity provider. Private application routes require verified sessions and product entitlements before access is granted.

PAYMENTS

Hosted payment handling

Subscription checkout is designed around a hosted payment provider-hosted payment surfaces. Raw card numbers and card security codes do not need to be stored by the application.

WEB DELIVERY

Hardened browser boundaries

Production responses use HTTPS protections including HSTS, content security policy, frame blocking, MIME-sniffing protection, restrictive browser permissions, and same-origin controls.

MARKET DATA

Licensed and labeled

Market data is sourced from licensed provider infrastructure and transformed into platform analytics. Data freshness and provenance are surfaced where available; unavailable data is not intentionally replaced with fabricated values.

INFRASTRUCTURE

Separated public and private services

Private service credentials and authentication stay outside the browser experience.

FINANCIAL BOUNDARY

No custody or order execution

The current product provides analytical software and market research tools. It does not presently custody customer assets or execute customer securities orders.

Security reporting: suspected security or privacy issues can be reported to support@veloxmortisai.com. This page does not claim SOC 2 certification, regulatory registration, guaranteed uptime, or platform-level PCI certification.