Security
Last updated October 3, 2026.
Wolf reads things that matter to you, so protecting them is the first thing we design for. This page explains, in plain terms, how that works.
Your own Wolf, walled off
- Every person gets their own Wolf from their very first text, running in its own sealed workspace. It can't see anyone else's conversations, memory, email or calendar, and no one else's Wolf can see yours.
- When your Wolf reaches your connected accounts, it does so only through commands fixed to you. A Wolf can't ask for another person's information, and it can't choose a different account.
- Those commands do a short list of specific things (like "search my email" or "add this event"). They can't open files on our server or reach anything else.
- Any Wolf that isn't on its list of allowed actions is refused automatically, without asking anyone.
Sharing only what you choose
- Finding a time with your circle or a group shares only whether you're free or busy, never what your events are. Every check is listed in your activity.
- You join a household or group only by tapping Accept yourself. A link alone, or someone knowing your number, is never enough to add you.
- Family chat answers come from a separate answerer that can't see anyone's private information.
Sensitive information
- Wolf never keeps passwords, card numbers, bank numbers or Social Security numbers. They are detected and removed before anything is stored, including in family chats and morning briefs.
- We never ask for the password to your Google, Microsoft or Apple account. Connections go through each company's own sign-in, and you can revoke them anytime.
- Wolf asks for your yes before it sends a message to someone, books something or spends money.
Encryption and storage
- Everything travels encrypted (HTTPS and TLS), between your phone, our websites, our server and the services Wolf uses.
- Wolf's server runs on Google Cloud, whose disks are encrypted. The sign-ins to your connected accounts are stored in encrypted storage, separately for each person, readable only by Wolf's server account.
- Our websites reach the server only through secure tunnels (Cloudflare and Tailscale); its web services aren't exposed directly to the internet.
Signing in
- app.moriahlabs.com has no passwords to steal. You sign in with a 6-digit code texted to your number, which expires in 10 minutes and allows only a few tries.
- Your session is a random token kept in a secure, HTTP-only cookie, and ends if your number is removed or moved. Every sign-in shows up in your activity.
- Our websites use strict browser security rules: no outside scripts beyond the bot check on the sign-up form, no tracking, and no embedding in other sites.
Texts that can be faked
Plain SMS texts can be faked to look like they came from someone else's number. If a number that uses iMessage suddenly sends a plain SMS, Wolf treats it as untrusted and won't act on that person's accounts from it.
Who can access the server
A very small number of people who run Wolf can access its server, only to keep it running and safe. We don't read your messages, email or family chats. Our logs record events and the last four digits of a number, never what you wrote.
Testing ourselves
We try to break Wolf's walls ourselves: planted fake secrets that no Wolf should ever see, automatic checks that every Wolf's settings are locked down, and reviews of anything that crosses between people. When we find a problem, we fix it first and close the gap before adding features.
If something goes wrong
If your information is ever exposed, we will tell you promptly, explain what happened and what we did about it, and tell any authorities the law requires.
Report a problem
Found a security issue? Email security@moriahlabs.com. We read every report, reply quickly, and won't pursue anyone who reports in good faith, doesn't access other people's information, and gives us time to fix it.
