Public traffic
Enforced
Website, web app, and public API
Public API load balancers redirect HTTP to HTTPS. S3 and SNS policies reject requests without TLS.
Security / Current boundary
What the hosted platform enforces, what varies by MCP, and what customers should keep outside the system.
Account and billing isolation covers the hosted control plane. Stateful MCP content follows product-specific namespace, persistence, and provider rules.
A scoped account key starts the request.
Auth0 establishes account identity.
Tenant, entitlement, rate, and usage checks run.
The selected MCP handles the bounded operation.
Outcome and usage impact can be recorded.
Customer content rule
Until an MCP documents a tenant-derived namespace and cross-tenant isolation tests, use non-sensitive evaluation data only.
Do not submit secrets, regulated data, private keys, sensitive personal data, or credentials in prompts and generic tool arguments.
“Enforced” applies only to the named surface. Each product-specific and provider boundary is listed with its control.
Enforced
Website, web app, and public API
Public API load balancers redirect HTTP to HTTPS. S3 and SNS policies reject requests without TLS.
Enforced
Hosted control plane
Auth0 authentication and tenant membership are checked before dispatch.
Enforced
Hosted tool calls
Product entitlement, rate limits, and available plan usage are checked.
Customer scoped
Repositories, clouds, browsers, and providers
External systems require separate least-privilege credentials. Account key scope covers Monarchic API access.
Product specific
Stateful tools and caller-supplied scopes
Published isolation guarantees require a documented tenant-derived namespace and cross-tenant tests for the product.
Enforced
Hosted AWS state and operational records
S3, DynamoDB, SQS, ECR, Secrets Manager, Lambda environment variables, and CloudWatch Logs use encryption at rest. Key ownership differs by service.
Provider boundary
Subscription payment details
Stripe handles full card details. Monarchic handles subscription status and billing records.
Checked across the dev, staging, production, and management accounts on August 22, 2026.
24 / 24 buckets
S3 uses SSE-S3 with AES-256. Every bucket policy denies requests when aws:SecureTransport is false.
6 / 6 tables
Every DynamoDB table uses encryption at rest, point-in-time recovery, and deletion protection.
4 / 4 accounts
Multi-Region CloudTrail records management events and global service activity with log-file validation. Audit buckets are encrypted, versioned, and retain current logs for 365 days.
4 / 4 accounts
GuardDuty monitors CloudTrail, DNS, and VPC flow-log sources. Optional protection plans remain disabled while foundational usage is measured during the trial.
4 / 4 accounts
Medium and higher GuardDuty findings reach confirmed alert subscribers. Management findings cross a scoped EventBridge route into the production alert path.
All reviewed
IAM Access Analyzer runs in all four accounts. On August 22, every current IAM finding was non-public, every live trust policy matched its reviewed hash, and no analyzer error remained.
3 / 3 topics
Dev, staging, and production SNS alert topics use separate customer-managed KMS keys with automatic rotation.
Encrypted
SQS queues use SQS-managed server-side encryption. ECR repositories use AES-256 encryption.
Encrypted
Secrets Manager, Lambda environment variables, and CloudWatch Logs use AWS encryption at rest. The production authorization-approval key is customer managed and rotates.
4 / 4 accounts
EBS encryption by default is enabled in dev, staging, production, and management. The audit found no active EBS volumes.
Versioned
Managed audit and artifact buckets retain noncurrent object versions for a bounded recovery window. Ephemeral sandbox buckets are excluded from this policy.
Hosted storage boundary
Production storage uses S3 and DynamoDB. MinIO is available only in local development.
Artifact creation, deployment, and product readiness are separate claims. Each needs its own evidence and each remains bounded to a product and environment.
A package or image exists and can be identified.
Deployment, isolation, and customer readiness require separate evidence.
A bounded runtime is deployed and responds to its checks.
Product gates and support commitments require separate qualification.
Applicable security, persistence, protocol, release, and operating checks have evidence.
Evidence remains scoped to the named product, environment, date, and test.
Enterprise audit exports and independent certification require separate agreements and evidence.
A hosted call can record
Visible outcome
Customers can see the resulting plan-usage impact for hosted calls in the authenticated product.
Explicit limit
Ask support about export, retention, or order-specific audit requirements before relying on operational records for compliance.
Certification: none claimed. Universal SLA: none published. Model-training rights follow the service terms; a broader public policy is pending.
Providers
A hosted MCP may call another provider only when its operation requires it. Product workflows name material provider and subprocess boundaries.
Retention
Account and subscription records remain while an account is active and as needed for billing, security, disputes, and legal obligations. Product artifacts remain until their product control or retention process removes them.
Backups, payment records, security evidence, and legally required records may remain for a limited period after deletion.
Security contact
Include the affected route, time, and a safe reproduction. Remove live credentials and sensitive customer data from the report.
support@monarchic.io