Trust & Security

MOBLUEHQ builds verification infrastructure for regulated work. This page summarizes how we handle data, who helps us run the service, and how to reach us about security.

Privacy posture

We collect only what we need to operate the site, respond to inquiries, and (when you use our products) deliver verification services. We do not sell personal information. Product traffic is designed so inference workloads can run without the scheduler seeing your underlying content — that architectural separation is central to the Blue substrate described in our portfolio.

See our Privacy Policy, our Terms of Service, and our Product Disclaimers for full details.

What actually leaves your machine, product by product

Most of this page describes what leaves your machine when it does. Five of our products send nothing at all: blueAlibi, blueFloor, blueIntent, blueParity and bluePipeline — our five evaluation tools — contain no outbound network code whatsoever. We verified that by reading the source for network calls, not by describing the architecture.

The local tiers of blueMonster and blueGlu are different, and we want to be exact about how. Your content stays on your machine. In blueMonster, the setting that would allow your ideas or search content to leave is off by default and the app does not send them unless you turn it on. But the app is not silent: by default it sends a meta-only heartbeat — health, version and counts, no content — roughly every fifteen minutes, it checks for updates, and signing in is a network call. That heartbeat is governed by a setting you can control from the app's settings — toggle the Telemetry switch to turn it off. See the Privacy Policy for exactly what the heartbeat sends and for additional options including "Unlink my data" if you have signed into your blueMonster account.

We had this wrong on this page until we re-read the code. It previously said these tiers never send anything anywhere, and said we had verified it. Content does not leave; metadata does. We are recording the correction here rather than quietly editing it away, because a page about what we send is the last place a silent edit belongs.

Data handling

  • Website & forms: Contact and investor messages are transmitted to our inbox provider and stored only as long as needed to respond. Launch-waitlist emails are transmitted the same way and used only to notify you when the product you asked about ships.
  • Local-only tools and tiers: the five evaluation tools and the local/free tiers named above process everything on-device. We never receive your inputs, outputs, or files from that usage.
  • Hosted and cloud-tier product data: when you use a hosted or cloud-enabled tier (blueMonster Premium, blueMonster Pro's cloud tier, blueGlu's bring-your-own-key or web-search features), verification inputs and outputs are processed to deliver signed receipts and, where applicable, are sent to the specific subprocessor named in the table below. Retention periods vary by plan and are documented in product agreements.
  • Logs: Operational logs (errors, latency, abuse signals) are kept for a limited period and access is restricted to personnel who need them.
  • Encryption: Data in transit uses TLS. Data at rest uses provider-managed encryption on our cloud infrastructure.
  • Deletion: You may request deletion of account-linked data by contacting us. Some records may be retained where required by law or for legitimate security purposes.

Subprocessors

Every party below that can receive data from a MOBLUEHQ product or the website is listed, with what it receives, which product sends it, and how we confirmed the status shown. This table is corrected as of 2026-09-06 against the currently deployed service and current code, not against product descriptions alone; it is updated whenever that changes.

MOBLUEHQ subprocessor list
Vendor What it receives Product(s) Status
Google (Vertex AI / Gemini) Content submitted through the cloud-overflow path, so Google can generate a result blueMonster Pro — cloud tier Active
Tavily Your search query, only when web search is enabled and you have consented blueGlu Active
Brave Search Your search query, only when web search is enabled and you have consented, and Brave is the provider selected blueGlu Active
A third-party AI provider of your choosing (bring-your-own-key) Your question or content, only when you supply your own API key for that provider blueGlu (BYOK); blueMonster Premium (tenant BYOK) User-configured
Anthropic Would process cloud-tier requests if this path ships blueMonster (potential future cloud tier) Planned
Stripe Payment and billing information blueMonster / blueGlu paid tiers Test mode only — not live
Vercel Website hosting & serverless functions Public website Active
FormSubmit Contact & inquiry form delivery Public website Active
Resend Transactional email Public website / future account infrastructure Planned
Plain Customer support inbox Public website / future account infrastructure Planned
WorkOS SSO & workforce identity Public website / future account infrastructure Planned

We do not sell personal information. Full detail on what each product shape collects, and your rights, is in our Privacy Policy.

Security contact

Report suspected vulnerabilities or security incidents to security@mobluehq.com. We aim to acknowledge reports within two business days.

Machine-readable contact details: /.well-known/security.txt

Vulnerability disclosure

We welcome good-faith reports from security researchers. Please:

  1. Email security@mobluehq.com with a description, reproduction steps, and impact assessment.
  2. Give us reasonable time to investigate and remediate before public disclosure (typically 90 days).
  3. Do not access, modify, or exfiltrate data belonging to other users.
  4. Do not perform denial-of-service testing against production systems.

We do not currently offer a paid bug bounty. We will credit researchers who request it and whose reports lead to a fix.

System status

Service availability and incident history: status.mobluehq.com