Monarchic / Independent AI R&D

Now / Agent enhancements Next / Agent workflows

Security / Current boundary

Current controls. Explicit limits.

What the hosted platform enforces, what varies by MCP, and what customers should keep outside the system.

How a hosted request is scoped.

Account and billing isolation covers the hosted control plane. Stateful MCP content follows product-specific namespace, persistence, and provider rules.

  1. Client

    A scoped account key starts the request.

  2. Identity

    Auth0 establishes account identity.

  3. Policy

    Tenant, entitlement, rate, and usage checks run.

  4. Runtime

    The selected MCP handles the bounded operation.

  5. Receipt

    Outcome and usage impact can be recorded.

Customer content rule

Use non-sensitive data by default.

Until an MCP documents a tenant-derived namespace and cross-tenant isolation tests, use non-sensitive evaluation data only.

Do not submit secrets, regulated data, private keys, sensitive personal data, or credentials in prompts and generic tool arguments.

Read the scope before the status.

“Enforced” applies only to the named surface. Each product-specific and provider boundary is listed with its control.

Control Status Scope Boundary

Public traffic

Enforced

Website, web app, and public API

Public API load balancers redirect HTTP to HTTPS. S3 and SNS policies reject requests without TLS.

Account identity

Enforced

Hosted control plane

Auth0 authentication and tenant membership are checked before dispatch.

Usage authorization

Enforced

Hosted tool calls

Product entitlement, rate limits, and available plan usage are checked.

External permissions

Customer scoped

Repositories, clouds, browsers, and providers

External systems require separate least-privilege credentials. Account key scope covers Monarchic API access.

MCP content isolation

Product specific

Stateful tools and caller-supplied scopes

Published isolation guarantees require a documented tenant-derived namespace and cross-tenant tests for the product.

Stored data

Enforced

Hosted AWS state and operational records

S3, DynamoDB, SQS, ECR, Secrets Manager, Lambda environment variables, and CloudWatch Logs use encryption at rest. Key ownership differs by service.

Payment cards

Provider boundary

Subscription payment details

Stripe handles full card details. Monarchic handles subscription status and billing records.

AWS controls in the hosted service.

Checked across the dev, staging, production, and management accounts on August 22, 2026.

Object storage

24 / 24 buckets

S3 uses SSE-S3 with AES-256. Every bucket policy denies requests when aws:SecureTransport is false.

Databases

6 / 6 tables

Every DynamoDB table uses encryption at rest, point-in-time recovery, and deletion protection.

Audit logging

4 / 4 accounts

Multi-Region CloudTrail records management events and global service activity with log-file validation. Audit buckets are encrypted, versioned, and retain current logs for 365 days.

Threat detection

4 / 4 accounts

GuardDuty monitors CloudTrail, DNS, and VPC flow-log sources. Optional protection plans remain disabled while foundational usage is measured during the trial.

Finding alerts

4 / 4 accounts

Medium and higher GuardDuty findings reach confirmed alert subscribers. Management findings cross a scoped EventBridge route into the production alert path.

External access

All reviewed

IAM Access Analyzer runs in all four accounts. On August 22, every current IAM finding was non-public, every live trust policy matched its reviewed hash, and no analyzer error remained.

Operational alerts

3 / 3 topics

Dev, staging, and production SNS alert topics use separate customer-managed KMS keys with automatic rotation.

Queues and images

Encrypted

SQS queues use SQS-managed server-side encryption. ECR repositories use AES-256 encryption.

Secrets and runtime

Encrypted

Secrets Manager, Lambda environment variables, and CloudWatch Logs use AWS encryption at rest. The production authorization-approval key is customer managed and rotates.

Volume defaults

4 / 4 accounts

EBS encryption by default is enabled in dev, staging, production, and management. The audit found no active EBS volumes.

Object recovery

Versioned

Managed audit and artifact buckets retain noncurrent object versions for a bounded recovery window. Ephemeral sandbox buckets are excluded from this policy.

Hosted storage boundary

Production storage uses S3 and DynamoDB. MinIO is available only in local development.

Three separate qualification states.

Artifact creation, deployment, and product readiness are separate claims. Each needs its own evidence and each remains bounded to a product and environment.

Built

Artifact

A package or image exists and can be identified.

Deployment, isolation, and customer readiness require separate evidence.

Running

Deployment

A bounded runtime is deployed and responds to its checks.

Product gates and support commitments require separate qualification.

Qualified

Readiness

Applicable security, persistence, protocol, release, and operating checks have evidence.

Evidence remains scoped to the named product, environment, date, and test.

A receipt is evidence of an operation.

Enterprise audit exports and independent certification require separate agreements and evidence.

A hosted call can record

server
tool
timestamp
duration
request size
response size
outcome
usage settlement
receipt ID

Visible outcome

Usage impact in the app.

Customers can see the resulting plan-usage impact for hosted calls in the authenticated product.

Explicit limit

Compliance requirements need review.

Ask support about export, retention, or order-specific audit requirements before relying on operational records for compliance.

Published assurance scope.

Certification: none claimed. Universal SLA: none published. Model-training rights follow the service terms; a broader public policy is pending.

Providers

AWS
Infrastructure and hosted runtimes
Auth0
Account identity
Stripe
Billing and payment boundary
Vercel
Public web surfaces

A hosted MCP may call another provider only when its operation requires it. Product workflows name material provider and subprocess boundaries.

Retention

Records follow their purpose.

Account and subscription records remain while an account is active and as needed for billing, security, disputes, and legal obligations. Product artifacts remain until their product control or retention process removes them.

Backups, payment records, security evidence, and legally required records may remain for a limited period after deletion.

Security contact

Report a suspected vulnerability.

Include the affected route, time, and a safe reproduction. Remove live credentials and sensitive customer data from the report.

support@monarchic.io