Security and governance built in
MonetizeKit is built with security, privacy, and governance as core requirements. From encryption to audit trails, we take protecting your data seriously — and we only publish what we can substantiate.
Start free — get an API keyCompliance-ready controls
Security controls and processes designed to support formal audits as we mature
Data encryption
Encryption in transit (TLS 1.2+) and at rest (AES-256) using industry-standard protocols
Privacy by design
Privacy controls aligned with GDPR — configurable retention, plus data export (DSAR) and right-to-erasure APIs for customer records
Security features
API key management
Scoped API keys with granular permissions, environment separation, and expiration controls
- Environment-specific keys (staging, production)
- Scoped permissions for least-privilege access
- Key expiration controls
- Usage monitoring with last-used tracking
Authentication & SSO
Managed authentication with social sign-in today; enterprise SSO and MFA are on our roadmap
- Social sign-in (Google, GitHub, and more)
- Managed sessions and secure credential handling
- SAML SSO and multi-factor authentication — Enterprise (coming soon)
- Just-in-time provisioning — planned
Audit logs
Audit trail of workspace changes for accountability and investigation
- Audit log of workspace and catalog changes
- Actor, resource, and change context captured
- Filterable audit views in the dashboard
- Export for reporting
Role-based access control
Role-based permissions and workspace isolation for controlled access
- Built-in roles for least-privilege access
- Workspace isolation between tenants
- Permission checks enforced on sensitive actions
- Custom roles — on our roadmap
Infrastructure security
Managed cloud infrastructure
MonetizeKit runs on security-first managed platforms — Vercel for the application and Supabase for the database — with encryption and automated backups built in.
- EncryptionTLS 1.2+ in transit, AES-256 at rest
- Managed platformHosted on Vercel with managed DDoS mitigation and firewall
- Managed databasePostgreSQL on Supabase with encryption at rest
- BackupsAutomated daily backups managed by Supabase
- MonitoringApplication error tracking and request logging
- SecretsCentralized secrets management, never committed to source
Compliance & trust
We publish only verified security and compliance artifacts. Rather than display unverified badges, we list what is available today and what is in progress in our Trust Center.
- Built on SOC 2-certified infrastructure providers (Vercel, Supabase)
- Privacy controls aligned with GDPR, expanding as our program matures
- Formal certifications will be listed only with shareable evidence
Built-in governance controls
Enterprise features that help you maintain control, compliance, and auditability
Approval workflows
Require approval for sensitive pricing changes, plan deprecations, and contract modifications
Environments
Keep staging and production configuration separate with per-environment API keys and settings
Webhook controls
Configure signed webhooks and delivery monitoring for secure integrations
Data privacy and residency
Data residency
Your data is stored in the United States by default. Additional regions are on our roadmap for teams with local data-protection requirements.
- US (default)
- EU — on the roadmap
Privacy controls
Controls to help you meet GDPR and privacy requirements — available today and expanding as our privacy program matures.
- Configurable data retention
- Data export (DSAR) for customer records via API
- Right to erasure (GDPR Article 17) via API
- Customer data anonymization on erasure
Questions about security?
Our team is here to answer your questions and provide documentation for your compliance requirements.