Security & Trust

Security is part of how we design software.

DataMonks considers security throughout system architecture, software development, deployment and operation. Controls vary according to the product, integration and deployment environment.

CONTROL_POSTURE // V1SECURITY MODEL
Identity & Access ControlsCONTROL AREA
Tenant IsolationCONTROL AREA
Secrets ManagementCONTROL AREA
Data Erasure ProcedurePROCESS AREA
CONTROLS VARY BY PRODUCT / INTEGRATION
Security Principles

Security controls should match the system and the risk

We use layered controls and deliberately avoid presenting planned controls or certifications as already achieved.

01

Identity & Access

Systems are designed to restrict access according to authenticated identity, role and operational need.

02

Data Protection

Appropriate protections are applied to data during transmission, storage and processing according to the system involved.

03

Tenant Isolation

Multi-tenant applications are designed to separate organisational data, permissions and operational context.

04

Secrets Management

Application credentials, API secrets and access tokens are handled through controlled mechanisms rather than exposed in application code or interfaces.

05

Secure Development

Security considerations are incorporated into architecture, implementation, testing, code review and deployment practices.

06

Logging & Monitoring

Operational and security-relevant events are designed to provide visibility for troubleshooting, investigation and incident response.

Software Lifecycle

Security across the software lifecycle

STAGE 01DesignContext & scope
STAGE 02BuildSystem design
STAGE 03TestProduction build
STAGE 04DeployVerification
STAGE 05ObserveControlled release
STAGE 06ImproveOperate & refine
Data & Integrations

Access should be limited to what the service needs.

DataMonks products may connect with authorised third-party APIs and business platforms. Integration permissions should be requested according to the functionality being provided. Access to a connected service does not imply unrestricted access to that service.

Least-privilege integration model

Authorised business or account administrator
Function-specific provider permissions
Controlled credential handling
Auditable operational context where applicable
Reliability & Recovery

Designing for failure as well as success

Applications are designed with backup, recovery, failure handling and service-resilience considerations appropriate to their deployment requirements. Specific recovery objectives depend on the product and customer arrangement.

Vulnerability Reporting

Report a security concern

If you believe you have identified a security issue involving a DataMonks website, product or service, contact our security function.

security@datamonks.io
Do not send secrets. Never include passwords, private keys, access tokens or other authentication secrets in an initial report.
A USEFUL INITIAL REPORT CAN INCLUDE01. Affected service or URL02. Clear description of the behaviour03. Safe reproduction steps04. Potential impact05. Your preferred contact details
Transparency

Clear claims. Verifiable status.

Security requirements and regulatory obligations differ across products, customers and deployment environments. DataMonks does not represent a certification or audit status as achieved unless it has formally been obtained.

STATUS_01

Security controls

Describe controls according to what is actually implemented for the relevant service.

STATUS_02

Third-party reviews

Provider assurances do not automatically become DataMonks certifications.

STATUS_03

Certifications

No certification is represented as obtained until formal evidence exists.

STATUS_04

Data protection

Product-specific roles and safeguards depend on the processing context.

Legal & Compliance

Privacy, legal and data governance resources

Public resources for provider review, customer diligence and data-subject requests.

RESOURCE_01

Privacy Policy

How DataMonks handles personal information.

View resource ↗
RESOURCE_02

Terms of Service

Base terms governing applicable services.

View resource ↗
RESOURCE_04

Subprocessors

Current launch infrastructure and communications providers.

View resource ↗
NEXT PHASE

Questions about security or data handling?

Use our official security and privacy channels so the right function can respond.