Status, not badges.
What is in place, what is being decided, and what we do not offer — with a date on it.
This page is generated from a single status file that we review and date. If a row says to be confirmed, that is the answer today. We would rather you read that than a badge we have not earned.
How to read this page
Managed cloud infrastructure we operate, built primarily on AWS. The backend is not self-hostable. Every row below carries one of five statuses:
- available In place today.
- in progress Actively underway; no completion date promised.
- on request Available under NDA or on request.
- not offered Not offered.
- to be confirmed Not decided or not verified yet. The note says what is outstanding.
Rows marked to be confirmed depend on a decision we have not made yet. They will change; the date at the bottom tells you when this page last did.
Attestation status
| Item | Status | Note |
|---|---|---|
| Encryption in transit | available | HTTPS on every app URL via an auto-renewing wildcard ACM certificate; file uploads and downloads use CloudFront signed URLs; artifact buckets are closed to the public and reachable only through CloudFront Origin Access Control. |
| SSO (Auth0 / SAML / Google / Firebase) | available | The platform supports SSO through Auth0, SAML, Google, and Firebase. |
| Audit logs | available | Readable in the product: the append-only deployment log (who triggered which version into which environment, when, with what result) and the optional row-level object change log, per record. MCP tool invocations are recorded on our side for quality and audit; a customer-facing export of that log is not offered today, and there is no log streaming or SIEM feed. |
| Vulnerability disclosure | available | Policy published at /security/vulnerability-disclosure and referenced from /.well-known/security.txt; reports go to the security mailbox. Safe-harbor wording is pending counsel review. |
| Data Processing Agreement | on request | Provided on request during procurement. The public draft at /legal/dpa is pending counsel review. |
| SOC 2 Type I | to be confirmed | No SOC 2 report is held today. Whether to pursue one is not decided; this row will read “in progress” only once an auditor is engaged, and “not offered” if we decide against it. |
| SOC 2 Type II | to be confirmed | Depends on the SOC 2 decision and an observation window. Not shown as in progress until an auditor is engaged. |
| ISO 27001 | to be confirmed | No ISO 27001 certification is held today. Whether to pursue one is not decided. |
| Penetration test | to be confirmed | No third-party penetration test is published today. If one has been performed, the firm, date, and availability of a summary letter will be listed here. |
| HIPAA / BAA | to be confirmed | No Business Associate Agreement is offered today. Until this row changes, do not treat the platform as suitable for regulated health data. |
| GDPR readiness | to be confirmed | The subprocessor list and DPA terms are to be confirmed before launch. We make no wider readiness claim today. |
| Data residency | to be confirmed | Apps and data run on managed cloud infrastructure we operate, built primarily on AWS. A specific region commitment is to be confirmed and is not promised until it is. |
| Encryption at rest (object data) | to be confirmed | Encryption at rest for object tables and file storage is to be confirmed and is not claimed until it is. We make no encryption-at-rest claim for per-environment configuration bundles. |
| Backups and restore | to be confirmed | Documented today: immutable version snapshots for custom frontends, frozen backup snapshots for platform solutions, and non-destructive rollback. Database backup schedule, retention, and recovery objectives are to be confirmed. |
| Incident response and breach notification | to be confirmed | No published incident-response commitment today. Notification terms are set in the Data Processing Agreement, available on request during procurement. |
| Uptime and availability | to be confirmed | No uptime or response-time commitment is published today. Availability terms, if any, are set in your agreement — ask during procurement and we will answer in writing. |
| Data retention and deletion | to be confirmed | Available today: every object is a real table you can query and export through a documented API. Retention windows and deletion timelines after termination are not confirmed yet. |
Subprocessors
Third parties that may process data on our behalf, with the purpose and the categories involved. The list below is to be confirmed before launch; the confirmed, versioned list lives at /legal/subprocessors and ships with the DPA.
| Subprocessor | Purpose | Data categories |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, compute, object storage, CDN, DNS, TLS certificates | Application data, build artifacts, uploaded files, logs |
| Supabase | CodeMonster control-plane state — app records, versions, deployments, edit sessions, tool telemetry | App metadata, deployment records, builder identifiers |
| SparkPost | Workflow email delivery (Email activity) | Recipient addresses and templated message content from workflows |
| Firebase (Google) | Push notifications (Notification activity); optional SSO provider | Device tokens, notification payloads; identity claims when used for SSO |
| Carbone | PDF generation (GenerateReport activity) | Report data passed to templates |
Your AI provider is not on this list. Prompts go from your agent to your provider under your own account; we are not a party to that traffic and do not process it.
Shared responsibility
The short version of who does what. The full model is part of the security overview.
- Operate the managed cloud infrastructure the platform and your apps run on, built primarily on AWS.
- Authenticate every request to the platform and enforce authorization server-side; the AI acts with the calling user's permissions, never its own.
- Issue and renew TLS certificates; keep artifact storage closed to the public.
- Enforce the promotion chain and role gates for custom frontends, keep rollback non-destructive, and keep the deployment audit log append-only.
- Provide the freeze flag, transaction preview, and change logs that let you govern what agents change.
- Hold and pay for your AI provider account, prompts, and keys — we never see, meter, or resell them.
- Decide who is in which group and which app role (owner / editor / viewer), and who may promote to production.
- Set up tenants, load the data, and choose which tenant each write names — the platform refuses a write that names none.
- Manage the secrets you place in per-environment configuration bundles, and what your custom frontends do with them. We make no encryption-at-rest claim for those bundles today, so treat them as build-time configuration, not a secret vault.
- Make end-user access decisions in the apps you build, and keep the desktop app and your agent up to date.
Request documents
Available on request during procurement:
- Security overview — the architecture, auth, tenancy, and governance material on this site in one document, with the fact registry it maps to.
- Data Processing Agreement — the DPA text; the public draft at /legal/dpa is pending counsel review.
- Subprocessor list — the confirmed, versioned list, also published at /legal/subprocessors.
Last reviewed
This page was last reviewed on 2026-08-15. Requests and corrections: security@codemonster.ai.