- Does the Mosaic architecture support secure communication over HTTPS/port 443 with TLS 1.2 or newer encryption?
- What is the tool utilized to conduct vulnerability scans?
- What is the name of the KMS provider?
- What is Mosaic's RPO?
- What is Mosaic's Cloud location?
Trust Center Updates
Mosaic Publishes Latest Penetration Test Results – No Vulnerabilities Found
We’re pleased to share that Mosaic has successfully completed its most recent Web Application Penetration Test, conducted by the independent cybersecurity firm Zaviant. The assessment resulted in zero identified vulnerabilities, reaffirming the strength of our application’s security posture.
Key Highlights
- No vulnerabilities found across any severity category: critical, high, medium, low, or informational.
- Full-scope testing covered unauthenticated and authenticated user roles (Org User, Org Admin, Super Admin).
- Core functionality, including file uploads, AI-powered model ingestion, and authentication mechanisms (SSO and MFA), was thoroughly tested with no issues discovered.
- Security best practices were observed throughout the application and supporting infrastructure, with Zaviant confirming strong resilience to attack.
This assessment was conducted in accordance with the Penetration Testing Execution Standard (PTES) methodology, encompassing reconnaissance, vulnerability analysis, exploitation attempts, and post-exploitation analysis.
The final report is now available for review in our Trust Center.
We remain committed to transparency and proactive risk management. Regular third-party assessments help ensure Mosaic continues to meet the highest standards of application security.
For any questions about the report, please contact us at support@mosaic.pe.

