Security & Governance

Security and governance built in

MonetizeKit is built with security, privacy, and governance as core requirements. From encryption to audit trails, we take protecting your data seriously — and we only publish what we can substantiate.

Start free — get an API key

Compliance-ready controls

Security controls and processes designed to support formal audits as we mature

Data encryption

Encryption in transit (TLS 1.2+) and at rest (AES-256) using industry-standard protocols

Privacy by design

Privacy controls aligned with GDPR — configurable retention, plus data export (DSAR) and right-to-erasure APIs for customer records

Security features

API key management

Scoped API keys with granular permissions, environment separation, and expiration controls

  • Environment-specific keys (staging, production)
  • Scoped permissions for least-privilege access
  • Key expiration controls
  • Usage monitoring with last-used tracking

Authentication & SSO

Managed authentication with social sign-in today; enterprise SSO and MFA are on our roadmap

  • Social sign-in (Google, GitHub, and more)
  • Managed sessions and secure credential handling
  • SAML SSO and multi-factor authentication — Enterprise (coming soon)
  • Just-in-time provisioning — planned

Audit logs

Audit trail of workspace changes for accountability and investigation

  • Audit log of workspace and catalog changes
  • Actor, resource, and change context captured
  • Filterable audit views in the dashboard
  • Export for reporting

Role-based access control

Role-based permissions and workspace isolation for controlled access

  • Built-in roles for least-privilege access
  • Workspace isolation between tenants
  • Permission checks enforced on sensitive actions
  • Custom roles — on our roadmap

Infrastructure security

Managed cloud infrastructure

MonetizeKit runs on security-first managed platforms — Vercel for the application and Supabase for the database — with encryption and automated backups built in.

  • Encryption
    TLS 1.2+ in transit, AES-256 at rest
  • Managed platform
    Hosted on Vercel with managed DDoS mitigation and firewall
  • Managed database
    PostgreSQL on Supabase with encryption at rest
  • Backups
    Automated daily backups managed by Supabase
  • Monitoring
    Application error tracking and request logging
  • Secrets
    Centralized secrets management, never committed to source

Compliance & trust

We publish only verified security and compliance artifacts. Rather than display unverified badges, we list what is available today and what is in progress in our Trust Center.

  • Built on SOC 2-certified infrastructure providers (Vercel, Supabase)
  • Privacy controls aligned with GDPR, expanding as our program matures
  • Formal certifications will be listed only with shareable evidence
Visit the Trust Center

Built-in governance controls

Enterprise features that help you maintain control, compliance, and auditability

Approval workflows

Require approval for sensitive pricing changes, plan deprecations, and contract modifications

Enterprise plan

Environments

Keep staging and production configuration separate with per-environment API keys and settings

All plans

Webhook controls

Configure signed webhooks and delivery monitoring for secure integrations

Pro and Enterprise

Data privacy and residency

Data residency

Your data is stored in the United States by default. Additional regions are on our roadmap for teams with local data-protection requirements.

  • US (default)
  • EU — on the roadmap

Privacy controls

Controls to help you meet GDPR and privacy requirements — available today and expanding as our privacy program matures.

  • Configurable data retention
  • Data export (DSAR) for customer records via API
  • Right to erasure (GDPR Article 17) via API
  • Customer data anonymization on erasure

Questions about security?

Our team is here to answer your questions and provide documentation for your compliance requirements.