Welcome to Morae Global's Trust Center.
At Morae Global, protecting the confidentiality, integrity, and availability of information is fundamental to how we operate. Security, privacy, and compliance are embedded throughout our people, processes, and technology, enabling us to deliver services our clients can trust.
This Trust Center provides transparency into our security and compliance programs, governance practices, and data protection measures. Here, you can learn more about our security posture, certifications, policies, and controls, as well as request access to relevant security documentation.
We are committed to maintaining the highest standards of information security and continuously enhancing our practices to safeguard the data entrusted to us.
Data Security
We follow industry best practices for data security. We are happy to provide more details about our data security practices upon request.
App Security
We take application security seriously and are putting together a program to monitor internal apps.
AI
We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.
ESG
We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.
Legal
We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.
Data Privacy
Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations.
Access Control
Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request.
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
- Is the documented information required by the information security management system and by this document controlled to ensure it is adequately protected (e.g. from loss of confidentiality, improper use, or loss of integrity)?
- Are any mobile devices with access to scoped data Constituent owned (BYOD)?
- For all organizational entities (e.g., vendor's vendors, subcontractors, fourth parties, Nth parties) is there a contractual relationship that extends obligations to each entity?
- Is there a records retention policy and retention schedule covering paper and electronic records, including email in support of applicable regulations, standards, and contractual requirements?
- Is there an DMZ environment within the network that transmits, processes, or stores scoped systems and data e.g., web servers, DNS, directory services, remote access, etc.?


