Security and isolation for every deployment
Every application on MoodLensAI runs in its own isolated container, with hardened defaults and automated checks. Here is what that actually means, in plain terms.
For anyone who wants to know what "managed hosting" actually means for security — running an AI-assisted side project or a small team's production app on shared infrastructure they don't manage themselves.
How it works
Per-tenant isolation
Each deployment gets its own project, network and volumes — never a shared network or shared filesystem with another customer's app.
Hardened container defaults
Deployments run without extra Linux capabilities, without access to the Docker socket or host filesystem, and as a non-root user wherever the runtime allows it.
Automated isolation checks
Each deployment's container configuration is checked automatically — flagging anything running privileged, as root, or with host-level access it should not have.
This is not a generic security claim: every deployment's isolation posture — privileged mode, root user, host network, Docker socket access — is checked automatically as part of ongoing platform monitoring, not just designed on paper. Every deployment also gets a freshly generated set of secrets, and all traffic to your app is encrypted over HTTPS/TLS.
Technical details ▼
- Isolation model
- Per-tenant containers, each with its own network and volumes
- Secrets
- A fresh set of deployment secrets is generated for every instance
- Transport
- HTTPS/TLS in transit; passwords are hashed, never stored in plain text
- Continuous review
- Container isolation is checked automatically, with an optional daily report — see Monitoring below
Limitations
MoodLensAI secures the hosting platform and the isolation between tenants — it does not audit or fix vulnerabilities in your own application code, and it is not a compliance certification: no SOC 2, ISO 27001, or similar claim is made. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Plans
This feature is included on every MoodLensAI plan — see fixed monthly pricing with no surprise bills.
Related features
Frequently asked questions
Can another customer's app access mine?
No. Each deployment runs in its own isolated container with its own network and volumes — there is no shared network or shared filesystem between tenants.
Do you run my containers as root?
No, not by default. Deployments run as a non-root user and without extra Linux capabilities wherever the runtime supports it.
Is MoodLensAI SOC 2 or ISO 27001 certified?
No. We describe our real security controls honestly above; we do not claim a compliance certification we do not hold.
Do you fix security bugs in my own application code?
No. We secure the hosting platform and the isolation between tenants; the security of your own application code remains your responsibility.
How are secrets and passwords handled?
Every deployment gets its own freshly generated secrets, transport is encrypted with HTTPS/TLS, and passwords are hashed, never stored in plain text.