Trust Center

The security, privacy, and data-handling practices behind MonetizeKit. We publish only what we can substantiate today.

Security controls

Encryption

TLS 1.2+ in transit and AES-256 at rest, using the managed encryption provided by our hosting and database platforms.

API key hashing

API keys are stored only as SHA-256 hashes; the plaintext key is shown once at creation and never persisted. A short prefix is retained for identification.

Tenant isolation

Every record is scoped to a workspace (and environment). Queries are constrained by workspace and environment on every request path.

Audit logging

An append-only audit log records workspace and catalog changes with actor, resource, and change context for accountability.

Subprocessors

MonetizeKit uses the following third-party subprocessors to operate the service. Each maintains its own security program; follow the links for their current documentation.

SubprocessorPurposeData processedRegion
VercelApplication hosting and content deliveryRequest metadata, logsUnited States
SupabaseManaged PostgreSQL database hostApplication and customer recordsUnited States
ClerkAuthentication and user managementAccount identities, sessionsUnited States
StripeBilling and payment processingBilling identifiers, subscription stateUnited States
PostHogProduct analyticsPseudonymous product eventsUnited States
ChecklySynthetic uptime and API monitoringHealth-check request metadataUnited States

Data handling & retention

Retention windows

  • Raw usage, evaluation, and ingestion logs
    90 days
  • Audit and activity logs
    Configurable per workspace (90–730 days), default 365 days
  • Monthly usage aggregates
    25 months

Data is stored in the United States by default. EU data residency is on our roadmap.

Data-subject rights (customer records)

  • Data export (DSAR)
    Export all personal data held for a customer record via the API or dashboard; delivered as a downloadable bundle through an expiring, tokenized link.
  • Right to erasure (GDPR Art. 17)
    Irreversibly anonymize a customer record while retaining non-identifying and legally-required financial records; every erasure is captured in the append-only audit log.

Agreements & policies

Coming when verifiable

Formal compliance reports (for example SOC 2) and trust-portal links will be listed here only with public or shareable evidence. Until then we do not display unverified badges.

Security questions or documentation requests: security@monetizekit.app