Moesif
Moesif is a cloud-based analytics, monetization, and governance platform for APIs and non-API events. It captures API calls, application events, and AI/LLM usage (such as prompts and tokens) for analytics, meters consumption for monetization, identifies customers, supports usage-based pricing and prepaid credits, and enforces governance such as quotas and limits.
Features
- Near-real-time analytics dashboards
- Event capture via SDKs,APIs, API gateways, and APIMs
- Support for API, non-API, and AI/LLM events
- Customer and tenant identification
- Usage metering for monetization and prepaid credits
- Billing platform integrations
- Configurable governance rules for quotas and limits
- Real-time governance evaluation
- Configurable alerts and notifications
- Data export via APIs and downloads
Benefits
- Gain visibility into API, application, and AI usage patterns
- Accurately measure consumption to support usage-based monetization models
- Identify customers and tenants consistently across all API interactions
- Reduce manual reporting through self-serve analytics dashboards
- Prevent service overuse by automatically enforcing usage limits
- Connect usage data to billing platforms natively
- Receive proactive notifications for usage thresholds or governance limits
- Export analytics data easily for audits, finance, and external reporting
- Make data-driven decisions using actual API and application usage data
- Define usage policies externally without changing application or gateway code
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 8 3 6 0 3 8 0 3 5 8 9 2 0 4
Contact
WSO2 (UK) LIMITED
Ricardo Diniz
Telephone: +44 (0)203-696-6510
Email: legal@wso2.com
About your service
- Service categories
-
Application Development and Deployment
Integration and orchestration
Integration software
- API Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Moesif extends most standard API gateways and API management platforms (APIMs), application backends, AI/LLM platforms, and external billing systems (such as Stripe, Chargebee, Recurly, and Zuora), and supports externalisation of Moesif analytics through embeddable templates, shared dashboards, and exports to business intelligence and data warehouse tools for reporting and auditing.
- Cloud deployment model
- Public cloud
- Service constraints
- Moesif is a cloud-native SaaS platform designed for high availability with no regularly scheduled downtime. Most updates are delivered via CI/CD using zero-downtime rolling deployments. If maintenance may impact availability, advance notice (typically 48–72 hours) is provided through the public status page. As a SaaS service, Moesif requires no customer hardware; integrations depend on the customer environment using supported SDKs, API gateways, and documented integrations. Service limits, including data retention, event volumes, and optional features such as dynamic sampling, are determined by the purchased service tier. Rare disruptions may occur due to underlying cloud provider outages.
- System requirements
-
- Outbound HTTPS connectivity for sending API and event data
- Supported SDKs or API gateway integrations in buyer environment
- Modern web browser for accessing the Moesif dashboard
- No software installation required on buyer systems
- No specific licences or antivirus requirements for virtual machines
User support
- Email or online ticketing support
- Yes
- Support response times
- Typically, within 5 minutes during business hours, and we only respond to high-priority issues on the weekend.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- A user can chat with a member of the Moesif team through our chat portal on the Moesif platform. In the portal, you can send text and images and request a call.
- Web chat accessibility testing
- None.
- Onsite support
- Yes
- Support levels
- Free plans can leverage community support and reach out to Moesif via chat. Growth plans have direct access to the Moesif team and can connect for training sessions and access technical resources. Enterprise plans have priority support and dedicated technical and business support. Growth plans include support and do not require an upgrade.
- Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- Moesif helps users get started through guided onboarding led by a dedicated Customer Success Manager, with access to technical experts for implementation support. Onboarding covers initial setup, integration using SDKs or API gateways, configuration of analytics dashboards, and setup of governance and monetization features. Moesif also runs tailored enablement sessions for customer teams including business, customer success, engineering, and product, supported by comprehensive online documentation and implementation guides.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Moesif allows users to extract their data at the end of the contract using built-in data export capabilities and APIs. Users can export analytics data, event data, and reports in standard formats (such as CSV or JSON) through the web interface or via APIs prior to service termination. Access to data is maintained for the duration of the contract and any applicable notice period, after which data is retained or deleted in accordance with the agreed service terms and data retention policy.
- End-of-contract process
- Moesif is provided as a subscription service for the duration of the contract. At the end of the contract, customers may renew, downgrade, or allow the subscription to expire. Prior to expiry, users can export their data using self-service export tools or APIs. After contract termination, access to the service is removed, and data is retained or deleted in accordance with the agreed data retention policy. The contract price includes access to the Moesif platform, standard onboarding, documentation, and support for supported integrations. Additional costs may apply for higher event volumes, extended data retention, or advanced features, depending on the service tier selected.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Moesif provides onboarding and offboarding documentation through publicly accessible HTML web pages that can be viewed using standard web browsers. Documentation is structured for readability and accessibility, supports keyboard navigation, and follows common web accessibility best practices.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Moesif is accessed through a secure, web-based user interface available via modern browsers. The interface provides interactive dashboards, filters, and reports for viewing API, application, and AI usage, along with configuration screens for governance rules, alerts, integrations, and data exports. The service also exposes APIs for programmatic access, integration, and embedding analytics into external applications or portals.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Moesif is accessed through a secure, web-based user interface using a modern browser, with integrations configured via SDKs, API gateways, or APIs in customer systems. Authorised users can view and modify analytics dashboards, explore usage data, configure alerts, manage governance rules, and export data based on their assigned role. Administrative users can manage workspaces, users, integrations, and billing-related settings. End users cannot modify customer application data, underlying infrastructure, or billing platform behavior directly through Moesif, and access is limited to the permissions granted by the organization.
- Accessibility testing
- Moesif designs its web user interface in line with standard web accessibility best practices, including the use of semantic HTML and ARIA (Accessible Rich Internet Applications) roles and attributes to support assistive technologies such as screen readers and keyboard navigation. While Moesif has not conducted formal or certified usability testing with users of assistive technologies, accessibility considerations are reviewed during UI development, and issues identified through testing or customer feedback are addressed as part of ongoing improvements.
- API
- Yes
- What users can and can't do using the API
- Moesif provides a Collector API and a Management API. Users set up the service by generating a Collector Application ID and sending API, non-API, or AI/LLM events to Moesif via the Collector API, either directly or through supported SDKs and API gateways. Users can make changes by updating the events and metadata they send, enabling additional event types, or using the Management API to query data and power embedded dashboards and externalised analytics. The Collector API is designed for high-volume event ingestion and does not modify customer systems or infrastructure, while the Management API is limited to authorised account-level operations. Service constraints such as event volumes and data retention are governed by the purchased service tier.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Moesif can be customized in terms of data captured, analytics views, governance rules, alerts, and integrations. Users customise the service by configuring SDKs, API gateways, or the Collector API to control what API, non-API, and AI/LLM events and metadata are sent, and by using the web interface to configure dashboards, segments, governance rules, alerts, embedded reports, and exports. Customisation is performed by authorised users based on role, with administrative users able to manage global settings, integrations, and governance policies, and standard users limited to viewing data and dashboards permitted by their access level.
Scaling
- Independence of resources
- Moesif uses a multi-tenant architecture with strong tenant-level data isolation to separate customer data and workloads. The ingestion layer (“collector”) is globally distributed and decoupled from the management portal and query services, with inbound data queued for asynchronous processing to maintain resilience during traffic spikes and prevent data loss. Moesif also applies capacity safeguards and is implementing per-tenant throttling and rate limiting to further ensure that unusually high demand from a single tenant is contained and does not affect other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Moesif provides service metrics related to API, application, and AI usage. Metrics include request and event volumes, response times and latency distributions, error rates, throughput over time, customer and tenant usage breakdowns, quota and limit consumption, and usage trends. Metrics are available through dashboards, filters, and exports to support operational monitoring, governance, and usage-based monetization.
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- Moesif protects data at rest using strong encryption and key management. All customer data ,including production data and backups is encrypted at rest with 256-bit AES encryption and encryption keys stored securely in a key management service such as Azure Key Vault. Data is stored in ISO/IEC 27001 and ISO/IEC 27017 compliant data centres with fault-tolerant storage and access controls. For customers with higher privacy requirements, Moesif supports an optional Secure Proxy with client-side encryption and customer-managed keys so that only the customer can decrypt sensitive data
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Moesif allows users to export and externalize their data through self-service data exports, APIs, and embeddable templates. Users can export analytics and event data in standard formats such as CSV and JSON, or externalise dashboards and reports using embeddable templates for use in external applications.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Parquet
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Moesif guarantees a service availability level of 99.97% as defined in its Master Services Agreement (MSA)- https://www.moesif.com/services-agreement. Availability is measured over the applicable service period and excludes agreed maintenance windows and events outside Moesif’s reasonable control. If the guaranteed availability level is not met, customers are eligible for service credits or refunds in accordance with the service credit provisions outlined in the Services Agreement.
- Approach to resilience
- Moesif is designed as a cloud-native, resilient SaaS platform. Moesif is hosted on major public cloud infrastructure that operates across multiple availability zones within a region, providing datacenter-level resilience, automated failover, and fault tolerance. Additional architectural details can be made available to buyers on request.
- Outage reporting
- Moesif reports service outages and incidents through a public status dashboard available at https://status.moesif.com, where users can view current service status, incident updates, and historical uptime information. Outage and maintenance information is published on the status page to provide transparency to users.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Moesif restricts access to management interfaces using role-based access controls (RBAC) and least-privilege permissions, ensuring that users can access only the features and data appropriate to their assigned role. Administrative actions are limited to authorised users within each customer workspace. Access by Moesif support personnel is restricted, logged, and provided only when necessary to deliver support, in accordance with internal access controls and customer agreements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Moesif follows documented information security policies covering areas such as access control, data protection, incident response, vulnerability management, and change management. These policies are reviewed regularly and are aligned with SOC 2 Type II requirements. Responsibility for information security is defined through a formal reporting structure, with designated security and engineering leadership overseeing policy implementation and compliance. Adherence to policies is enforced through technical controls, access restrictions, monitoring, internal reviews, and independent third-party audits as part of Moesif’s SOC 2 compliance program
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Moesif manages configuration and change through defined operational and security policies. Service components, source code, documentation, and releases are tracked throughout their lifecycle using a version control system with controlled access approved by system administrators. Changes are developed, reviewed, tested, and labelled through standard release processes, with security impact considered as part of change assessment. Moesif also maintains an emergency change process that authorises designated members to validate, apply, and release critical security patches or bug fixes outside the standard change workflow when necessary to protect system security and availability, with such changes logged and reviewed retrospectively.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Moesif manages vulnerabilities through a defined vulnerability management process. Potential threats are assessed using automated vulnerability scanning, third-party penetration testing, and ongoing review of application and infrastructure components. Vulnerabilities are prioritised based on severity and impact, with critical and high-risk issues addressed on an expedited basis and patches deployed through controlled release processes. Moesif monitors emerging threats using security tooling, cloud provider advisories, industry vulnerability databases such as CVEs, and trusted security research sources. Cloud infrastructure is regularly scanned using native AWS and Azure security tools to identify misconfigurations and unpatched assets.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Moesif uses protective monitoring to detect and respond to potential security incidents. Potential compromises are identified through automated scanning and monitoring, user and system reporting, and analysis of anomalous system behaviour and access violations. When a potential compromise is detected, incidents are logged, assessed, and investigated in accordance with a defined incident response procedure, including impact assessment, containment, remediation, evidence preservation, and post-incident review. Incidents are triaged and investigated by severity, with preliminary investigations initiated within defined timeframes and high-severity incidents handled on an expedited basis by designated security and engineering personnel.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Moesif maintains documented incident management processes, including predefined procedures for common security and operational events, such as service outages, security incidents, and data-handling issues. Users can report incidents by contacting Moesif support through established support channels. Incidents are logged, triaged, and managed according to severity, and incident reports or post-incident summaries are provided to affected customers as appropriate, in line with contractual and regulatory requirements.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Moesif offers a 14-day free trial, allowing users to evaluate advanced platform features based on the published pricing tiers at www.moesif.com/pricing. At the end of the trial, the account automatically transitions to the free tier. WSO2 customers may also be eligible for an extended 90-day Enterprise trial, subject to agreement.
- Link to free trial
- Sign up at www.moesif.com
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 20%
- Between £250,000 and £500,000
- 20%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Wednesday 24 April 2024
- What the ISO/IEC 27001 doesn’t cover
-
The certification scope is limited to the WSO2 Digital Operations function, which oversees the access management of the WSO2 Infrastructure and the overall management of endpoints. However, certain controls will be applicable across the organization - e.g., conducting background verification on new staff prior to onboarding, ensuring a suitable Endpoint Protection solution is installed on all computers, etc.
Software development and provision of related services are NOT in the scope of the certification. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- ControlCase
- PCI DSS accreditation date
- Saturday 24 May 2025
- What the PCI DSS doesn’t cover
- Choreo, Devant, and Bijira are within the scope of the PCI DSS certification. All other solutions and offerings are NOT in scope.
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- SOC 2 Type 2
- HIPAA
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
-