SECURITY
Security commitments
The commitments we stand behind in contract language. Full controls, subprocessors, and the compliance roadmap live on our security page.
This page states Monroe’s security commitments in plain terms for contracts and security review. For the full picture (the live controls, the subprocessor table with regions, and the compliance roadmap) see getmonroe.com/security, which is the canonical security surface.
What we commit to
- All public traffic is served over HTTPS, and production data stores are designed for provider-managed encryption at rest.
- Your workspace data is never used to train foundation models, and we do not sell it.
- Connector scopes are least-privilege by default; users explicitly approve every scope at OAuth time.
- Every run is logged (who, where, when, credits) so each action is auditable.
- Personal data is deleted within 30 days of account termination, except as required by law.
Compliance
- SOC 2 Type I in progress with Vanta (Q3 2026 target); Type II to follow.
- GDPR / UK GDPR: DPA available on request.
- HIPAA / BAA and CCPA requirements are reviewed case by case through the DPA review process.
Subprocessors
Our current subprocessor list, with regions, is published on the canonical sub-processor table at getmonroe.com/security. We notify customers 30 days before adding a new subprocessor.
Reporting a vulnerability
security@getmonroe.com reaches the on-call engineer (PGP key on request).