Back to home

Security

Updated August 11, 2026

This page describes only the security mechanisms actually in place in Monarch OS as of the date above — never a certification or guarantee we do not hold. See also the Privacy Policy and the Terms.

Organization isolation

Each client business's data (knowledge base, conversations, leads, tasks, settings) is technically separated from every other client business's data, enforced at the database level itself (Supabase Row Level Security policies) — not only in application code. One organization never accesses another's data.

Accounts and authentication

Account creation requires a password of at least 8 characters. Passwords are never stored in plain text. A verification email is sent at signup; the account remains usable immediately — verification is a trust signal, not a blocking gate.

Connectors (Gmail, Google Calendar, Google Contacts)

Every connection to an external tool (Gmail, Google Calendar, Google Contacts — WhatsApp Business coming soon) is made with only the permissions actually needed for that employee's use — never broader access than what's used. A business can remove a connector at any time from its dashboard. If an access token expires or is revoked, Monarch OS detects it and shows it as such on the connectors page, never pretending the connector still works.

Connector credential storage

Access tokens for external tools are encrypted at rest (Supabase Vault) and are only decrypted by the server-side components that genuinely need them to act on your behalf — never transmitted to or readable from the browser.

AI action governance

Every type of action an AI employee can take has a risk level. The simplest actions run automatically. Actions that commit the business are, depending on the setting chosen by the business, either automatic or subject to human approval before execution. The most sensitive actions always require human approval — no exception is possible today.

Any pending proposal appears in a single validation queue, reviewable at any time. Every action proposed, approved, rejected, or executed is logged in a reviewable history, including who approved or rejected it, and when.

AI-side isolation between businesses

The context given to an AI model to respond on behalf of a given business contains only that business's information — never the knowledge base, conversations, or settings of another client organization.

Payments

Payments are processed by Stripe. Monarch OS never receives or stores full card details — they pass only through Stripe's own infrastructure.

Public entry point protection

Forms accessible without authentication (for example a contact form embedded on a client business's own website) are protected by rate limiting intended to prevent abuse — exact thresholds are deliberately not published here.

Infrastructure

Monarch OS relies on Supabase (database, authentication) and Stripe (payments) as its main sub-processors. See the Privacy Policy for the full list and applicable contractual framework.

To learn more

Privacy Policy, Terms, and Contact for any security question.