Password protection
Support for password-strength rules and checks against known compromised passwords helps reject weak credentials at signup and reset.
The controls behind your app should work together, too. Moora brings login, access, and credentials into the same system.
Know who is signing in, which apps they can use, and how those apps connect to your services. Explore each layer in the preview.
Managed sign-in establishes who is requesting access before the app opens.
Signing in and having permission are separate decisions. Choose the people and groups each app is for.
Use authorized service connections for your app’s requests. Keep the credentials managed in one place.
Interactive illustration. Sample identity, groups, and connection.
Managed authentication brings modern sign-in capabilities into one flow, so every app does not need to reinvent login.
Support for password-strength rules and checks against known compromised passwords helps reject weak credentials at signup and reset.
An authenticator-app code adds another check at sign-in when MFA is enabled, helping protect an account if a password is exposed.
Passkeys use cryptographic proof tied to the sign-in site. When enabled, they offer a phishing-resistant alternative to passwords.
Configurable session lifetimes and inactivity limits help keep a sign-in active only as long as it should be.
Supported SAML and OIDC connections let teams use their company identity provider and its existing sign-in policies.
Email verification and account recovery flows help confirm account ownership, with identity managed outside your app’s custom screens.
Authentication methods and policies depend on workspace configuration. Company SSO follows your identity provider’s authentication policies.
Bring permissions and connections into the same system. Keep the choices clear, from the person opening an app to the service it calls.
Keep authentication and app permissions together. Give people access to the apps they need, with a clear place to manage those decisions.
Manage service authorization in one connection flow. Reduce the need to copy and maintain separate credentials across your apps.
Authorize the permissions your app needs. Read and write capabilities follow the connected service’s API and the permissions granted to it.
For organizations with formal assurance requirements, Moora’s Enterprise roadmap includes a dedicated compliance program.
Information security management
Planned certification of an information security management system, covering how security risks are assessed, managed, and reviewed.
Independent assurance over time
A planned independent examination of relevant controls and their operating effectiveness over a defined period.
ISO 27001 certification and the SOC 2 Type II examination are planned, not yet completed. The related compliance offering is intended for Enterprise only.
Explore EnterpriseNo. Login establishes identity. App access determines which apps a person or group can open. Moora brings both into the same workspace.
Login methods and policies depend on workspace configuration. For company SSO, authentication requirements are controlled by the organization’s identity provider.
No. Available actions depend on the service, the connected account, and the permissions authorized for that connection.
Not yet. ISO 27001 certification and a SOC 2 Type II examination are planned. The related compliance offering is intended for Enterprise only; completed documentation will be shared when available.