Executive summary
HKISG assessed Moxie Co. Ltd. (the-moxie.com) — a Hong Kong event planning, marketing, and customer-relation agency — under methodology v2026.2. Result: 4.5 TrustScore (Excellent) and 88/100.
Excellent is not a perfect 5.0. This label means strong, buyer-usable controls with limited managed gaps — appropriate for an agency whose core business is experiences and growth programmes, not security products. The review focuses on client data, campaign access, live-event trust, GenAI/deepfake programme hygiene, and delivery discipline when brands trust Moxie with audiences and personal information.
What we assessed
- Client and attendee data handling across events, CRM / loyalty, and telemarketing workflows
- Access hygiene for online marketing accounts (SEO, social, paid campaigns)
- Hong Kong delivery discipline — briefing quality, on-site controls, and post-event wrap-up
- Vendor / subcontractor visibility for production and AV partners
- Incident readiness language and escalation pathways for programme sponsors
- GenAI tool use, bans on feeding client lists into public LLMs, and deepfake-aware verification around live programmes
- Transparency of what data is collected, retained, and deleted after a campaign
- Passive public-website hygiene of the-moxie.com (TLS redirect + security headers)
Out of scope: creative quality awards; media-buy ROI certification; substitute for formal PDPO legal advice; scoring Moxie as an AI product vendor; penetration testing, Wix plugin audits, or authenticated CMS scans.
Domain scorecard (v2026.2)
| Domain | Score | Notes |
|---|---|---|
| Governance & accountability | 13 / 15 | Name a security owner on every SOW |
| Protective controls | 16 / 18 | Ad/CMS hygiene strong; quarterly MFA evidence |
| Detection & response | 14 / 18 | Daytime OK; after-hours path soft |
| AI security & model governance | 16 / 18 | Need written GenAI / list-feeding rules |
| Supplier & resilience | 12 / 14 | Flag AV/production substitutions earlier |
| Evidence quality | 17 / 17 | Packs strong when requested — make them default |
| Total | 88 / 100 | Strong band; not reference-grade 90+ |
Buyer lenses below are sector views mapped into these domains — not a second competing score.
Why 4.5 (not 5.0)
- Hong Kong delivery readiness — 4.8 — Local presence, venue fluency, bilingual practice.
- Client data handling — 4.6 — Guest-list control, suppression, project close-out access removal.
- Campaign & web security hygiene — 4.5 — Shared-tool least privilege above typical agency norms.
- Gaps holding the score below 5.0 — after-hours security contact; subcontractor change tracking; PDPO/AI data map not yet default in every proposal; GenAI list-feeding bans need to be written, not assumed; public homepage missing CSP / framing headers on passive check.
AI security & deepfake lenses
Moxie is scored as a programme operator using AI-era tools, not as a model vendor. Under Methodology AI lenses:
Inventory & ownership
List which GenAI tools staff may use for copy, design variants, translation, or audience insight — and who approves them.
Data & model integrity
Do not paste attendee, CRM, or telemarketing lists into public LLMs. Put that ban in the SOW. Prefer enterprise tools with contractual data controls when GenAI is required.
Human & deepfake risk
Live events and executive appearances raise deepfake / voice-clone payment and access-fraud risk. Brief on-site leads on verification rituals for last-minute “CEO said pay / grant access” requests. See AI Security and Governance.
Third-party tools
Ad platforms’ AI features can move data in ways sponsors did not expect — disclose and restrict.
Public website hygiene — the-moxie.com
HKISG ran a passive public-surface check on 1 Aug 2026 against https://www.the-moxie.com (Wix-hosted). This is not a penetration test and does not mean “no vulnerabilities on the site.”
Grade: Fair+ (3.8 / 5)
| Check | Result |
|---|---|
| HTTP → HTTPS redirect | Pass (the-moxie.com → www) |
| HSTS | Pass (max-age=31556952) |
| X-Content-Type-Options | Pass (nosniff) |
| Content-Security-Policy | Warn — not observed |
X-Frame-Options / frame-ancestors |
Warn — not observed |
| Referrer-Policy | Warn — not observed |
For agency buyers: ask whether event microsites and campaign landing pages inherit the same HTTPS/HSTS baseline, and whether form endpoints that collect attendee data have separate hardening evidence.
PDPO-oriented data map (buyer template)
Ask Moxie (or any agency) to fill this one-pager before kickoff:
- What is collected — attendee, CRM, calling list, badge scans, form fills
- Where it lives — systems, regions, who has admin
- Who can access — named roles; contractors included
- How long retained — and deletion proof at programme close
- Cross-border — any transfer outside Hong Kong
- Subprocessors — AV, SMS, ESP, GenAI tools
- Incident contact — daytime and after-hours
Align with your own policies via Hong Kong data privacy wiki.
Buyer lenses (category narrative)
Client data handling — 4.6
Careful list treatment; retention windows improving but should be automatic on every SOW.
Campaign & web security hygiene — 4.5
Ad-account and CMS access practices mature for agency size. Require MFA evidence quarterly.
Hong Kong delivery readiness — 4.8
Kwun Tong base and brand-programme muscle make Moxie easy to operationalise locally.
Vendor & supplier diligence — 4.3
Core team strong; subcontractor substitutions need earlier security notification (target: 48 hours).
Incident readiness — 4.2
Daytime escalation works. Publish after-hours security / data-incident contact; define a 60-minute live-event exposure response outline.
AI & deepfake programme hygiene — 4.3
Awareness present; written GenAI bans and deepfake verification briefs should ship by default.
Public website hygiene — 3.8
HTTPS + HSTS + nosniff are in place. Missing CSP / framing / Referrer-Policy headers are the main public-site gaps on this passive check.
Limitations (read these)
- A TrustScore is not a creative award or a guarantee against data incidents.
- Scope is trust and information-handling practice around Moxie’s Hong Kong programmes.
- Practitioner reviews are verified HKISG programme participants and assessment-panel synthesis.
- Scores expire; valid until 30 Jul 2027 unless material change requires earlier reassessment.
Retest cues
- Default data map + GenAI ban clause in proposal templates
- Published after-hours security contact
- 48-hour subcontractor change notification in SOWs
- Quarterly MFA evidence for shared ad/CMS accounts
- Deepfake verification brief for on-site leads
- Public-site CSP / framing / Referrer-Policy (or platform attestation covering them)
Buyer checklist for Hong Kong organisations
- Require the seven-point data map before kickoff.
- Require MFA and named owners on shared ad / CMS accounts.
- Put subcontractor change notification into the SOW (48-hour rule).
- Confirm after-hours contact for suspected data exposure during live events.
- Ban uploading personal data into public GenAI tools — in writing.
- Brief on-site leads on deepfake / voice-clone verification rituals.
- Align retention with your PDPO-oriented policies.
How to read this vs a platform review
Moxie is a services / agency trust profile. Do not compare its category names one-for-one with a product platform review such as Fortinet. Compare instead: scope honesty, dated evidence, gap transparency, and whether limitations are readable.