Account access
- Email and password, or sign in with Google.
- Two step verification with an authenticator app, available to every account in Settings.
- Passkeys can be linked from Settings, so this device proves it is you with its own lock, face or fingerprint. A passkey also answers the confirm step before money moves or your data is downloaded.
- Changing your password while signed in requires your current password. New passwords are checked against known breached passwords and refused if they appear in one.
- Sign out everywhere, from Settings, ends every other signed in device.
Data protection
- Row-level security on every public table. A request can only read or write rows it is explicitly authorised for.
- Integration tokens for connected accounts are held server side, never sent to the browser, and encrypted at rest with AES-256-GCM under a key the database never holds.
- TLS in transit for every request, edge to origin to database.
The money rail
- Card details are handled by our PCI-DSS Level 1 payments processor. MusicVerse servers never see a card number.
- The ledger is append-only and double-entry. Balances are projections of the log; nothing is overwritten.
- Money never moves through a client write. Every transfer is a server-authorised function with an idempotency key enforced as a database unique constraint inside the same transaction.
- Inbound payment webhooks are signature-verified before they touch the ledger.
- Withdrawing money and changing where it lands ask you to confirm it is you again, with your passkey, authenticator code or password. The check is spent on the server, once, so the interface cannot skip it.
- Downloading a copy of your own data asks for the same confirmation, and every confirmation, refusal and export is written to your account activity.
The MV.AI layer
Every figure on the platform is computed deterministically in Postgres from your data and inspectable benchmarks. Claude is handed the number and narrates the sentence. The model never invents a price, a forecast, or a fee. Predictions are written to a predictions table at the moment they are made and graded against the outcome.
Engineering controls
- Automated scanning of database tables, policies and privileged functions.
- Privileged functions are
SECURITY DEFINERwith pinnedsearch_pathand explicit role guards. - Audit log on privileged actions and on account changes, kept 12 months and then deleted by a nightly job. You can read your own entries in Settings.
- Backups of database and storage with point-in-time recovery.
Reporting a vulnerability
If you believe you have found a security issue, email security@musicverse.app. Please include reproduction steps and avoid testing against accounts that are not yours. We acknowledge within 72 hours and do not pursue good-faith research.