Identity & Access
Systems are designed to restrict access according to authenticated identity, role and operational need.
DataMonks considers security throughout system architecture, software development, deployment and operation. Controls vary according to the product, integration and deployment environment.
We use layered controls and deliberately avoid presenting planned controls or certifications as already achieved.
Systems are designed to restrict access according to authenticated identity, role and operational need.
Appropriate protections are applied to data during transmission, storage and processing according to the system involved.
Multi-tenant applications are designed to separate organisational data, permissions and operational context.
Application credentials, API secrets and access tokens are handled through controlled mechanisms rather than exposed in application code or interfaces.
Security considerations are incorporated into architecture, implementation, testing, code review and deployment practices.
Operational and security-relevant events are designed to provide visibility for troubleshooting, investigation and incident response.
DataMonks products may connect with authorised third-party APIs and business platforms. Integration permissions should be requested according to the functionality being provided. Access to a connected service does not imply unrestricted access to that service.
Applications are designed with backup, recovery, failure handling and service-resilience considerations appropriate to their deployment requirements. Specific recovery objectives depend on the product and customer arrangement.
If you believe you have identified a security issue involving a DataMonks website, product or service, contact our security function.
Security requirements and regulatory obligations differ across products, customers and deployment environments. DataMonks does not represent a certification or audit status as achieved unless it has formally been obtained.
Describe controls according to what is actually implemented for the relevant service.
Provider assurances do not automatically become DataMonks certifications.
No certification is represented as obtained until formal evidence exists.
Product-specific roles and safeguards depend on the processing context.
Public resources for provider review, customer diligence and data-subject requests.
How DataMonks handles personal information.
View resource ↗Base terms governing applicable services.
View resource ↗How to request deletion of eligible data.
View resource ↗Current launch infrastructure and communications providers.
View resource ↗Use our official security and privacy channels so the right function can respond.