Trust Center
The security, privacy, and data-handling practices behind MonetizeKit. We publish only what we can substantiate today.
Security controls
Encryption
TLS 1.2+ in transit and AES-256 at rest, using the managed encryption provided by our hosting and database platforms.
API key hashing
API keys are stored only as SHA-256 hashes; the plaintext key is shown once at creation and never persisted. A short prefix is retained for identification.
Tenant isolation
Every record is scoped to a workspace (and environment). Queries are constrained by workspace and environment on every request path.
Audit logging
An append-only audit log records workspace and catalog changes with actor, resource, and change context for accountability.
Subprocessors
MonetizeKit uses the following third-party subprocessors to operate the service. Each maintains its own security program; follow the links for their current documentation.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Vercel | Application hosting and content delivery | Request metadata, logs | United States |
| Supabase | Managed PostgreSQL database host | Application and customer records | United States |
| Clerk | Authentication and user management | Account identities, sessions | United States |
| Stripe | Billing and payment processing | Billing identifiers, subscription state | United States |
| PostHog | Product analytics | Pseudonymous product events | United States |
| Checkly | Synthetic uptime and API monitoring | Health-check request metadata | United States |
Data handling & retention
Retention windows
- Raw usage, evaluation, and ingestion logs90 days
- Audit and activity logsConfigurable per workspace (90–730 days), default 365 days
- Monthly usage aggregates25 months
Data is stored in the United States by default. EU data residency is on our roadmap.
Data-subject rights (customer records)
- Data export (DSAR)Export all personal data held for a customer record via the API or dashboard; delivered as a downloadable bundle through an expiring, tokenized link.
- Right to erasure (GDPR Art. 17)Irreversibly anonymize a customer record while retaining non-identifying and legally-required financial records; every erasure is captured in the append-only audit log.
Agreements & policies
- Data Processing Agreement (DPA) — available on request for customers with a data-protection requirement. Email security@monetizekit.app and we will provide our current DPA.
- Security overview — encryption, access control, and auditability
- Privacy Policy
- Terms of Service
Coming when verifiable
Formal compliance reports (for example SOC 2) and trust-portal links will be listed here only with public or shareable evidence. Until then we do not display unverified badges.
Security questions or documentation requests: security@monetizekit.app