CodeMonster.ai · by Knomatic
Security & governance

Status, not badges.

What is in place, what is being decided, and what we do not offer — with a date on it.

This page is generated from a single status file that we review and date. If a row says to be confirmed, that is the answer today. We would rather you read that than a badge we have not earned.

How to read this page

Managed cloud infrastructure we operate, built primarily on AWS. The backend is not self-hostable. Every row below carries one of five statuses:

  • available In place today.
  • in progress Actively underway; no completion date promised.
  • on request Available under NDA or on request.
  • not offered Not offered.
  • to be confirmed Not decided or not verified yet. The note says what is outstanding.

Rows marked to be confirmed depend on a decision we have not made yet. They will change; the date at the bottom tells you when this page last did.

Attestation status

ItemStatusNote
Encryption in transit available HTTPS on every app URL via an auto-renewing wildcard ACM certificate; file uploads and downloads use CloudFront signed URLs; artifact buckets are closed to the public and reachable only through CloudFront Origin Access Control.
SSO (Auth0 / SAML / Google / Firebase) available The platform supports SSO through Auth0, SAML, Google, and Firebase.
Audit logs available Readable in the product: the append-only deployment log (who triggered which version into which environment, when, with what result) and the optional row-level object change log, per record. MCP tool invocations are recorded on our side for quality and audit; a customer-facing export of that log is not offered today, and there is no log streaming or SIEM feed.
Vulnerability disclosure available Policy published at /security/vulnerability-disclosure and referenced from /.well-known/security.txt; reports go to the security mailbox. Safe-harbor wording is pending counsel review.
Data Processing Agreement on request Provided on request during procurement. The public draft at /legal/dpa is pending counsel review.
SOC 2 Type I to be confirmed No SOC 2 report is held today. Whether to pursue one is not decided; this row will read “in progress” only once an auditor is engaged, and “not offered” if we decide against it.
SOC 2 Type II to be confirmed Depends on the SOC 2 decision and an observation window. Not shown as in progress until an auditor is engaged.
ISO 27001 to be confirmed No ISO 27001 certification is held today. Whether to pursue one is not decided.
Penetration test to be confirmed No third-party penetration test is published today. If one has been performed, the firm, date, and availability of a summary letter will be listed here.
HIPAA / BAA to be confirmed No Business Associate Agreement is offered today. Until this row changes, do not treat the platform as suitable for regulated health data.
GDPR readiness to be confirmed The subprocessor list and DPA terms are to be confirmed before launch. We make no wider readiness claim today.
Data residency to be confirmed Apps and data run on managed cloud infrastructure we operate, built primarily on AWS. A specific region commitment is to be confirmed and is not promised until it is.
Encryption at rest (object data) to be confirmed Encryption at rest for object tables and file storage is to be confirmed and is not claimed until it is. We make no encryption-at-rest claim for per-environment configuration bundles.
Backups and restore to be confirmed Documented today: immutable version snapshots for custom frontends, frozen backup snapshots for platform solutions, and non-destructive rollback. Database backup schedule, retention, and recovery objectives are to be confirmed.
Incident response and breach notification to be confirmed No published incident-response commitment today. Notification terms are set in the Data Processing Agreement, available on request during procurement.
Uptime and availability to be confirmed No uptime or response-time commitment is published today. Availability terms, if any, are set in your agreement — ask during procurement and we will answer in writing.
Data retention and deletion to be confirmed Available today: every object is a real table you can query and export through a documented API. Retention windows and deletion timelines after termination are not confirmed yet.

Subprocessors

Third parties that may process data on our behalf, with the purpose and the categories involved. The list below is to be confirmed before launch; the confirmed, versioned list lives at /legal/subprocessors and ships with the DPA.

SubprocessorPurposeData categories
Amazon Web Services (AWS) Hosting, compute, object storage, CDN, DNS, TLS certificates Application data, build artifacts, uploaded files, logs
Supabase CodeMonster control-plane state — app records, versions, deployments, edit sessions, tool telemetry App metadata, deployment records, builder identifiers
SparkPost Workflow email delivery (Email activity) Recipient addresses and templated message content from workflows
Firebase (Google) Push notifications (Notification activity); optional SSO provider Device tokens, notification payloads; identity claims when used for SSO
Carbone PDF generation (GenerateReport activity) Report data passed to templates

Your AI provider is not on this list. Prompts go from your agent to your provider under your own account; we are not a party to that traffic and do not process it.

Shared responsibility

The short version of who does what. The full model is part of the security overview.

We
  • Operate the managed cloud infrastructure the platform and your apps run on, built primarily on AWS.
  • Authenticate every request to the platform and enforce authorization server-side; the AI acts with the calling user's permissions, never its own.
  • Issue and renew TLS certificates; keep artifact storage closed to the public.
  • Enforce the promotion chain and role gates for custom frontends, keep rollback non-destructive, and keep the deployment audit log append-only.
  • Provide the freeze flag, transaction preview, and change logs that let you govern what agents change.
You
  • Hold and pay for your AI provider account, prompts, and keys — we never see, meter, or resell them.
  • Decide who is in which group and which app role (owner / editor / viewer), and who may promote to production.
  • Set up tenants, load the data, and choose which tenant each write names — the platform refuses a write that names none.
  • Manage the secrets you place in per-environment configuration bundles, and what your custom frontends do with them. We make no encryption-at-rest claim for those bundles today, so treat them as build-time configuration, not a secret vault.
  • Make end-user access decisions in the apps you build, and keep the desktop app and your agent up to date.

Request documents

Available on request during procurement:

  • Security overview — the architecture, auth, tenancy, and governance material on this site in one document, with the fact registry it maps to.
  • Data Processing Agreement — the DPA text; the public draft at /legal/dpa is pending counsel review.
  • Subprocessor list — the confirmed, versioned list, also published at /legal/subprocessors.

Last reviewed

This page was last reviewed on 2026-08-15. Requests and corrections: security@codemonster.ai.