- Are image templates for containers version-controlled, maintained, and checked for vulnerabilities, with no hardcoded secret keys?
- Does Mosaic use guardrails to secure the production environment, preventing misconfigurations and the deployment of insecure resources?
- Does Mosaic create custom AI models in-house, and if so, how is training performed on those models?
- How do users of Mosaic enter financial data into the platform?
- How is AI utilized in the Mosaic platform?
Trust Center Updates
Mosaic Updates
Mosaic Publishes Latest Penetration Test Results – No Vulnerabilities Found
We’re pleased to share that Mosaic has successfully completed its most recent Web Application Penetration Test, conducted by the independent cybersecurity firm Zaviant. The assessment resulted in zero identified vulnerabilities, reaffirming the strength of our application’s security posture.
Key Highlights
- No vulnerabilities found across any severity category: critical, high, medium, low, or informational.
- Full-scope testing covered unauthenticated and authenticated user roles (Org User, Org Admin, Super Admin).
- Core functionality, including file uploads, AI-powered model ingestion, and authentication mechanisms (SSO and MFA), was thoroughly tested with no issues discovered.
- Security best practices were observed throughout the application and supporting infrastructure, with Zaviant confirming strong resilience to attack.
This assessment was conducted in accordance with the Penetration Testing Execution Standard (PTES) methodology, encompassing reconnaissance, vulnerability analysis, exploitation attempts, and post-exploitation analysis.
The final report is now available for review in our Trust Center.
We remain committed to transparency and proactive risk management. Regular third-party assessments help ensure Mosaic continues to meet the highest standards of application security.
For any questions about the report, please contact us at support@mosaic.pe.

