Skip to main content

Help us improve the Digital Marketplace - send your feedback

WSO2 (UK) LIMITED

Moesif

Moesif is a cloud-based analytics, monetization, and governance platform for APIs and non-API events. It captures API calls, application events, and AI/LLM usage (such as prompts and tokens) for analytics, meters consumption for monetization, identifies customers, supports usage-based pricing and prepaid credits, and enforces governance such as quotas and limits.

Features

  • Near-real-time analytics dashboards
  • Event capture via SDKs,APIs, API gateways, and APIMs
  • Support for API, non-API, and AI/LLM events
  • Customer and tenant identification
  • Usage metering for monetization and prepaid credits
  • Billing platform integrations
  • Configurable governance rules for quotas and limits
  • Real-time governance evaluation
  • Configurable alerts and notifications
  • Data export via APIs and downloads

Benefits

  • Gain visibility into API, application, and AI usage patterns
  • Accurately measure consumption to support usage-based monetization models
  • Identify customers and tenants consistently across all API interactions
  • Reduce manual reporting through self-serve analytics dashboards
  • Prevent service overuse by automatically enforcing usage limits
  • Connect usage data to billing platforms natively
  • Receive proactive notifications for usage thresholds or governance limits
  • Export analytics data easily for audits, finance, and external reporting
  • Make data-driven decisions using actual API and application usage data
  • Define usage policies externally without changing application or gateway code

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@wso2.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 8 3 6 0 3 8 0 3 5 8 9 2 0 4

Contact

WSO2 (UK) LIMITED Ricardo Diniz
Telephone: +44 (0)203-696-6510
Email: legal@wso2.com

About your service

Service categories

Application Development and Deployment

Integration and orchestration

Integration software

  • API Management Software
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Moesif extends most standard API gateways and API management platforms (APIMs), application backends, AI/LLM platforms, and external billing systems (such as Stripe, Chargebee, Recurly, and Zuora), and supports externalisation of Moesif analytics through embeddable templates, shared dashboards, and exports to business intelligence and data warehouse tools for reporting and auditing.
Cloud deployment model
Public cloud
Service constraints
Moesif is a cloud-native SaaS platform designed for high availability with no regularly scheduled downtime. Most updates are delivered via CI/CD using zero-downtime rolling deployments. If maintenance may impact availability, advance notice (typically 48–72 hours) is provided through the public status page. As a SaaS service, Moesif requires no customer hardware; integrations depend on the customer environment using supported SDKs, API gateways, and documented integrations. Service limits, including data retention, event volumes, and optional features such as dynamic sampling, are determined by the purchased service tier. Rare disruptions may occur due to underlying cloud provider outages.
System requirements
  • Outbound HTTPS connectivity for sending API and event data
  • Supported SDKs or API gateway integrations in buyer environment
  • Modern web browser for accessing the Moesif dashboard
  • No software installation required on buyer systems
  • No specific licences or antivirus requirements for virtual machines

User support

Email or online ticketing support
Yes
Support response times
Typically, within 5 minutes during business hours, and we only respond to high-priority issues on the weekend.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
A user can chat with a member of the Moesif team through our chat portal on the Moesif platform. In the portal, you can send text and images and request a call.
Web chat accessibility testing
None.
Onsite support
Yes
Support levels
Free plans can leverage community support and reach out to Moesif via chat. Growth plans have direct access to the Moesif team and can connect for training sessions and access technical resources. Enterprise plans have priority support and dedicated technical and business support. Growth plans include support and do not require an upgrade.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Moesif helps users get started through guided onboarding led by a dedicated Customer Success Manager, with access to technical experts for implementation support. Onboarding covers initial setup, integration using SDKs or API gateways, configuration of analytics dashboards, and setup of governance and monetization features. Moesif also runs tailored enablement sessions for customer teams including business, customer success, engineering, and product, supported by comprehensive online documentation and implementation guides.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Moesif allows users to extract their data at the end of the contract using built-in data export capabilities and APIs. Users can export analytics data, event data, and reports in standard formats (such as CSV or JSON) through the web interface or via APIs prior to service termination. Access to data is maintained for the duration of the contract and any applicable notice period, after which data is retained or deleted in accordance with the agreed service terms and data retention policy.
End-of-contract process
Moesif is provided as a subscription service for the duration of the contract. At the end of the contract, customers may renew, downgrade, or allow the subscription to expire. Prior to expiry, users can export their data using self-service export tools or APIs. After contract termination, access to the service is removed, and data is retained or deleted in accordance with the agreed data retention policy. The contract price includes access to the Moesif platform, standard onboarding, documentation, and support for supported integrations. Additional costs may apply for higher event volumes, extended data retention, or advanced features, depending on the service tier selected.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Moesif provides onboarding and offboarding documentation through publicly accessible HTML web pages that can be viewed using standard web browsers. Documentation is structured for readability and accessibility, supports keyboard navigation, and follows common web accessibility best practices.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Moesif is accessed through a secure, web-based user interface available via modern browsers. The interface provides interactive dashboards, filters, and reports for viewing API, application, and AI usage, along with configuration screens for governance rules, alerts, integrations, and data exports. The service also exposes APIs for programmatic access, integration, and embedding analytics into external applications or portals.
Accessibility standards
None or don’t know
Description of accessibility
Moesif is accessed through a secure, web-based user interface using a modern browser, with integrations configured via SDKs, API gateways, or APIs in customer systems. Authorised users can view and modify analytics dashboards, explore usage data, configure alerts, manage governance rules, and export data based on their assigned role. Administrative users can manage workspaces, users, integrations, and billing-related settings. End users cannot modify customer application data, underlying infrastructure, or billing platform behavior directly through Moesif, and access is limited to the permissions granted by the organization.
Accessibility testing
Moesif designs its web user interface in line with standard web accessibility best practices, including the use of semantic HTML and ARIA (Accessible Rich Internet Applications) roles and attributes to support assistive technologies such as screen readers and keyboard navigation. While Moesif has not conducted formal or certified usability testing with users of assistive technologies, accessibility considerations are reviewed during UI development, and issues identified through testing or customer feedback are addressed as part of ongoing improvements.
API
Yes
What users can and can't do using the API
Moesif provides a Collector API and a Management API. Users set up the service by generating a Collector Application ID and sending API, non-API, or AI/LLM events to Moesif via the Collector API, either directly or through supported SDKs and API gateways. Users can make changes by updating the events and metadata they send, enabling additional event types, or using the Management API to query data and power embedded dashboards and externalised analytics. The Collector API is designed for high-volume event ingestion and does not modify customer systems or infrastructure, while the Management API is limited to authorised account-level operations. Service constraints such as event volumes and data retention are governed by the purchased service tier.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Moesif can be customized in terms of data captured, analytics views, governance rules, alerts, and integrations. Users customise the service by configuring SDKs, API gateways, or the Collector API to control what API, non-API, and AI/LLM events and metadata are sent, and by using the web interface to configure dashboards, segments, governance rules, alerts, embedded reports, and exports. Customisation is performed by authorised users based on role, with administrative users able to manage global settings, integrations, and governance policies, and standard users limited to viewing data and dashboards permitted by their access level.

Scaling

Independence of resources
Moesif uses a multi-tenant architecture with strong tenant-level data isolation to separate customer data and workloads. The ingestion layer (“collector”) is globally distributed and decoupled from the management portal and query services, with inbound data queued for asynchronous processing to maintain resilience during traffic spikes and prevent data loss. Moesif also applies capacity safeguards and is implementing per-tenant throttling and rate limiting to further ensure that unusually high demand from a single tenant is contained and does not affect other users.

Analytics

Service usage metrics
Yes
Metrics types
Moesif provides service metrics related to API, application, and AI usage. Metrics include request and event volumes, response times and latency distributions, error rates, throughput over time, customer and tenant usage breakdowns, quota and limit consumption, and usage trends. Metrics are available through dashboards, filters, and exports to support operational monitoring, governance, and usage-based monetization.
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Moesif protects data at rest using strong encryption and key management. All customer data ,including production data and backups is encrypted at rest with 256-bit AES encryption and encryption keys stored securely in a key management service such as Azure Key Vault. Data is stored in ISO/IEC 27001 and ISO/IEC 27017 compliant data centres with fault-tolerant storage and access controls. For customers with higher privacy requirements, Moesif supports an optional Secure Proxy with client-side encryption and customer-managed keys so that only the customer can decrypt sensitive data
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Moesif allows users to export and externalize their data through self-service data exports, APIs, and embeddable templates. Users can export analytics and event data in standard formats such as CSV and JSON, or externalise dashboards and reports using embeddable templates for use in external applications.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • PDF
  • Parquet
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Moesif guarantees a service availability level of 99.97% as defined in its Master Services Agreement (MSA)- https://www.moesif.com/services-agreement. Availability is measured over the applicable service period and excludes agreed maintenance windows and events outside Moesif’s reasonable control. If the guaranteed availability level is not met, customers are eligible for service credits or refunds in accordance with the service credit provisions outlined in the Services Agreement.
Approach to resilience
Moesif is designed as a cloud-native, resilient SaaS platform. Moesif is hosted on major public cloud infrastructure that operates across multiple availability zones within a region, providing datacenter-level resilience, automated failover, and fault tolerance. Additional architectural details can be made available to buyers on request.
Outage reporting
Moesif reports service outages and incidents through a public status dashboard available at https://status.moesif.com, where users can view current service status, incident updates, and historical uptime information. Outage and maintenance information is published on the status page to provide transparency to users.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Moesif restricts access to management interfaces using role-based access controls (RBAC) and least-privilege permissions, ensuring that users can access only the features and data appropriate to their assigned role. Administrative actions are limited to authorised users within each customer workspace. Access by Moesif support personnel is restricted, logged, and provided only when necessary to deliver support, in accordance with internal access controls and customer agreements.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Moesif follows documented information security policies covering areas such as access control, data protection, incident response, vulnerability management, and change management. These policies are reviewed regularly and are aligned with SOC 2 Type II requirements. Responsibility for information security is defined through a formal reporting structure, with designated security and engineering leadership overseeing policy implementation and compliance. Adherence to policies is enforced through technical controls, access restrictions, monitoring, internal reviews, and independent third-party audits as part of Moesif’s SOC 2 compliance program
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Moesif manages configuration and change through defined operational and security policies. Service components, source code, documentation, and releases are tracked throughout their lifecycle using a version control system with controlled access approved by system administrators. Changes are developed, reviewed, tested, and labelled through standard release processes, with security impact considered as part of change assessment. Moesif also maintains an emergency change process that authorises designated members to validate, apply, and release critical security patches or bug fixes outside the standard change workflow when necessary to protect system security and availability, with such changes logged and reviewed retrospectively.
Vulnerability management type
Undisclosed
Vulnerability management approach
Moesif manages vulnerabilities through a defined vulnerability management process. Potential threats are assessed using automated vulnerability scanning, third-party penetration testing, and ongoing review of application and infrastructure components. Vulnerabilities are prioritised based on severity and impact, with critical and high-risk issues addressed on an expedited basis and patches deployed through controlled release processes. Moesif monitors emerging threats using security tooling, cloud provider advisories, industry vulnerability databases such as CVEs, and trusted security research sources. Cloud infrastructure is regularly scanned using native AWS and Azure security tools to identify misconfigurations and unpatched assets.
Protective monitoring type
Undisclosed
Protective monitoring approach
Moesif uses protective monitoring to detect and respond to potential security incidents. Potential compromises are identified through automated scanning and monitoring, user and system reporting, and analysis of anomalous system behaviour and access violations. When a potential compromise is detected, incidents are logged, assessed, and investigated in accordance with a defined incident response procedure, including impact assessment, containment, remediation, evidence preservation, and post-incident review. Incidents are triaged and investigated by severity, with preliminary investigations initiated within defined timeframes and high-severity incidents handled on an expedited basis by designated security and engineering personnel.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Moesif maintains documented incident management processes, including predefined procedures for common security and operational events, such as service outages, security incidents, and data-handling issues. Users can report incidents by contacting Moesif support through established support channels. Incidents are logged, triaged, and managed according to severity, and incident reports or post-incident summaries are provided to affected customers as appropriate, in line with contractual and regulatory requirements.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Moesif offers a 14-day free trial, allowing users to evaluate advanced platform features based on the published pricing tiers at www.moesif.com/pricing. At the end of the trial, the account automatically transitions to the free tier. WSO2 customers may also be eligible for an extended 90-day Enterprise trial, subject to agreement.
Link to free trial
Sign up at www.moesif.com

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
20%
Between £250,000 and £500,000
20%
Between £500,001 and £1,000,000
20%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
UKAS
ISO/IEC 27001 accreditation date
Wednesday 24 April 2024
What the ISO/IEC 27001 doesn’t cover
The certification scope is limited to the WSO2 Digital Operations function, which oversees the access management of the WSO2 Infrastructure and the overall management of endpoints. However, certain controls will be applicable across the organization - e.g., conducting background verification on new staff prior to onboarding, ensuring a suitable Endpoint Protection solution is installed on all computers, etc.

Software development and provision of related services are NOT in the scope of the certification.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
ControlCase
PCI DSS accreditation date
Saturday 24 May 2025
What the PCI DSS doesn’t cover
Choreo, Devant, and Bijira are within the scope of the PCI DSS certification. All other solutions and offerings are NOT in scope.
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
  • SOC 2 Type 2
  • HIPAA

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@wso2.com. Tell them what format you need. It will help if you say what assistive technology you use.