We'd rather tell you exactly what's live today versus what's on the roadmap than let a features page imply more than we've actually shipped.
Two-factor authentication
Real TOTP-based 2FA (RFC 6238), enrolled via QR code, with one-time backup codes. Available today on every account under Settings → Security.
Role-based access control
Every user in a workspace holds a role — owner, admin, editor, or viewer — that governs billing access, connection management, campaign approval rights, and read-only visibility. Enforced on every server action, not just hidden in the UI.
Audit logs
Every AI-proposed action, human approval or rejection, and settings change is written to an append-only audit log — there's no code path that updates or deletes an entry once it's recorded.
SOC 2 Type II
We build to SOC 2-aligned control discipline from day one — access control, audit logging, change management — so a formal audit doesn't require retrofitting the system later. We are not yet certified; certification is scheduled once we have enterprise customers requiring it.
Compliance & GDPR
GDPR posture — data processing agreement template, right-to-export, right-to-delete — is designed against the real schema from the start rather than bolted on later. A formal compliance program (including sub-processor list and DPA execution) ships alongside SOC 2 readiness.
Enterprise SSO & SCIM
SAML/SSO and SCIM user provisioning are planned for the Enterprise phase of the roadmap — today, sign-in supports email+password with 2FA and OAuth (Google, Microsoft, Apple, GitHub) where a workspace has connected the provider.
White label
Custom branding for agencies reselling MUZ ADS to their own clients is on our roadmap — not available yet.
Custom AI models
Bringing your own model or fine-tuned endpoint instead of our default AI Gateway is a planned Enterprise capability, not available yet.
Dedicated infrastructure
Isolated, single-tenant infrastructure for customers who require it is on the Enterprise roadmap. Every workspace today runs on shared, tenant-isolated infrastructure with organization-scoped data access.
Ask us directly — especially if you're evaluating us for an enterprise deployment.
Contact Security