Executive summary

HKISG assessed Moxie Co. Ltd. (the-moxie.com) — a Hong Kong event planning, marketing, and customer-relation agency — under methodology v2026.2. Result: 4.5 TrustScore (Excellent) and 88/100.

Excellent is not a perfect 5.0. This label means strong, buyer-usable controls with limited managed gaps — appropriate for an agency whose core business is experiences and growth programmes, not security products. The review focuses on client data, campaign access, live-event trust, GenAI/deepfake programme hygiene, and delivery discipline when brands trust Moxie with audiences and personal information.

What we assessed

  • Client and attendee data handling across events, CRM / loyalty, and telemarketing workflows
  • Access hygiene for online marketing accounts (SEO, social, paid campaigns)
  • Hong Kong delivery discipline — briefing quality, on-site controls, and post-event wrap-up
  • Vendor / subcontractor visibility for production and AV partners
  • Incident readiness language and escalation pathways for programme sponsors
  • GenAI tool use, bans on feeding client lists into public LLMs, and deepfake-aware verification around live programmes
  • Transparency of what data is collected, retained, and deleted after a campaign
  • Passive public-website hygiene of the-moxie.com (TLS redirect + security headers)

Out of scope: creative quality awards; media-buy ROI certification; substitute for formal PDPO legal advice; scoring Moxie as an AI product vendor; penetration testing, Wix plugin audits, or authenticated CMS scans.

Domain scorecard (v2026.2)

Domain Score Notes
Governance & accountability 13 / 15 Name a security owner on every SOW
Protective controls 16 / 18 Ad/CMS hygiene strong; quarterly MFA evidence
Detection & response 14 / 18 Daytime OK; after-hours path soft
AI security & model governance 16 / 18 Need written GenAI / list-feeding rules
Supplier & resilience 12 / 14 Flag AV/production substitutions earlier
Evidence quality 17 / 17 Packs strong when requested — make them default
Total 88 / 100 Strong band; not reference-grade 90+

Buyer lenses below are sector views mapped into these domains — not a second competing score.

Why 4.5 (not 5.0)

  1. Hong Kong delivery readiness — 4.8 — Local presence, venue fluency, bilingual practice.
  2. Client data handling — 4.6 — Guest-list control, suppression, project close-out access removal.
  3. Campaign & web security hygiene — 4.5 — Shared-tool least privilege above typical agency norms.
  4. Gaps holding the score below 5.0 — after-hours security contact; subcontractor change tracking; PDPO/AI data map not yet default in every proposal; GenAI list-feeding bans need to be written, not assumed; public homepage missing CSP / framing headers on passive check.

AI security & deepfake lenses

Moxie is scored as a programme operator using AI-era tools, not as a model vendor. Under Methodology AI lenses:

Inventory & ownership

List which GenAI tools staff may use for copy, design variants, translation, or audience insight — and who approves them.

Data & model integrity

Do not paste attendee, CRM, or telemarketing lists into public LLMs. Put that ban in the SOW. Prefer enterprise tools with contractual data controls when GenAI is required.

Human & deepfake risk

Live events and executive appearances raise deepfake / voice-clone payment and access-fraud risk. Brief on-site leads on verification rituals for last-minute “CEO said pay / grant access” requests. See AI Security and Governance.

Third-party tools

Ad platforms’ AI features can move data in ways sponsors did not expect — disclose and restrict.

Public website hygiene — the-moxie.com

HKISG ran a passive public-surface check on 1 Aug 2026 against https://www.the-moxie.com (Wix-hosted). This is not a penetration test and does not mean “no vulnerabilities on the site.”

Grade: Fair+ (3.8 / 5)

Check Result
HTTP → HTTPS redirect Pass (the-moxie.comwww)
HSTS Pass (max-age=31556952)
X-Content-Type-Options Pass (nosniff)
Content-Security-Policy Warn — not observed
X-Frame-Options / frame-ancestors Warn — not observed
Referrer-Policy Warn — not observed

For agency buyers: ask whether event microsites and campaign landing pages inherit the same HTTPS/HSTS baseline, and whether form endpoints that collect attendee data have separate hardening evidence.

PDPO-oriented data map (buyer template)

Ask Moxie (or any agency) to fill this one-pager before kickoff:

  1. What is collected — attendee, CRM, calling list, badge scans, form fills
  2. Where it lives — systems, regions, who has admin
  3. Who can access — named roles; contractors included
  4. How long retained — and deletion proof at programme close
  5. Cross-border — any transfer outside Hong Kong
  6. Subprocessors — AV, SMS, ESP, GenAI tools
  7. Incident contact — daytime and after-hours

Align with your own policies via Hong Kong data privacy wiki.

Buyer lenses (category narrative)

Client data handling — 4.6

Careful list treatment; retention windows improving but should be automatic on every SOW.

Campaign & web security hygiene — 4.5

Ad-account and CMS access practices mature for agency size. Require MFA evidence quarterly.

Hong Kong delivery readiness — 4.8

Kwun Tong base and brand-programme muscle make Moxie easy to operationalise locally.

Vendor & supplier diligence — 4.3

Core team strong; subcontractor substitutions need earlier security notification (target: 48 hours).

Incident readiness — 4.2

Daytime escalation works. Publish after-hours security / data-incident contact; define a 60-minute live-event exposure response outline.

AI & deepfake programme hygiene — 4.3

Awareness present; written GenAI bans and deepfake verification briefs should ship by default.

Public website hygiene — 3.8

HTTPS + HSTS + nosniff are in place. Missing CSP / framing / Referrer-Policy headers are the main public-site gaps on this passive check.

Limitations (read these)

  • A TrustScore is not a creative award or a guarantee against data incidents.
  • Scope is trust and information-handling practice around Moxie’s Hong Kong programmes.
  • Practitioner reviews are verified HKISG programme participants and assessment-panel synthesis.
  • Scores expire; valid until 30 Jul 2027 unless material change requires earlier reassessment.

Retest cues

  1. Default data map + GenAI ban clause in proposal templates
  2. Published after-hours security contact
  3. 48-hour subcontractor change notification in SOWs
  4. Quarterly MFA evidence for shared ad/CMS accounts
  5. Deepfake verification brief for on-site leads
  6. Public-site CSP / framing / Referrer-Policy (or platform attestation covering them)

Buyer checklist for Hong Kong organisations

  1. Require the seven-point data map before kickoff.
  2. Require MFA and named owners on shared ad / CMS accounts.
  3. Put subcontractor change notification into the SOW (48-hour rule).
  4. Confirm after-hours contact for suspected data exposure during live events.
  5. Ban uploading personal data into public GenAI tools — in writing.
  6. Brief on-site leads on deepfake / voice-clone verification rituals.
  7. Align retention with your PDPO-oriented policies.

How to read this vs a platform review

Moxie is a services / agency trust profile. Do not compare its category names one-for-one with a product platform review such as Fortinet. Compare instead: scope honesty, dated evidence, gap transparency, and whether limitations are readable.