Clear controls, clear boundaries, and evidence for how Model Monster protects customer data.
Model Monster helps teams govern AI systems using structured architecture evidence grounded in system components, dependencies, and data flows. Teams use that evidence to evaluate policies, identify risks, document decisions, and maintain review records.
Trust matters twice: customers need confidence in the systems they are reviewing, and they need confidence in the platform helping them do that work.
We publish the controls we operate, define the boundaries that protect customer data, and support deeper diligence on request.
A layered security model
Model Monster uses a layered security model built on least privilege, organization isolation, and reviewable evidence. Core controls include:
Access & isolation
- Private backend services
- Authorization checks at protected service boundaries
- Organization- and team-level role-based access control
- Organization-scoped OIDC SSO support
Data protection
- TLS encryption for data transmitted to and from Model Monster
- Managed edge protection and web application firewalling
- A physically separated governance database for each organization, with organization governance material stored within an isolated tenant namespace
- Full-disk encryption for servers and additional AES-256 encryption for PostgreSQL backup archives
Monitoring & assurance
- Audit logs for system architecture and version changes; review submissions, decisions, and cancellations; policy and risk changes; restricted-document changes; use-case catalog changes; organization SSO changes; and team and membership administration
- Continuous security monitoring and hardened deployment images
- Documented incident response and business continuity processes
How We Protect Customer Data
-
01 / 06
Organization-Isolated Storage
Each organization has a physically separated governance database, with organization governance material stored within an isolated tenant namespace. System records, documents, media, reports, and other governance assets remain within that organization boundary. Routing, application authorization, and team permissions enforce access across those boundaries.
-
02 / 06
Data Protection
Data transmitted to and from Model Monster is encrypted in transit with TLS. All servers use full-disk encryption, and PostgreSQL backup archives receive additional AES-256 encryption. OIDC client secrets are protected through application-level encryption, and API credentials through one-way hashing.
Governance data and related assets remain within the organization's isolated tenant namespace and are protected by scoped routing, authorization, and application permissions.
Every API key is bound to its issuing user and their permissions. Keys may optionally be further restricted to one team and its organization.
-
03 / 06
AI Use
Model Monster uses Model Monster to govern and secure its own AI use. We do not use customer data to train, fine-tune, or improve generative AI models unless the customer explicitly opts in.
-
04 / 06
Access and Identity
Organization- and team-level roles control administrative and product access. Access to an individual system and the actions available within it derive from its owning team and the user's application permissions.
For customer organizations, Model Monster supports organization-scoped OIDC SSO.
Internally, workforce access is governed through MFA-protected accounts and least-privilege access.
-
05 / 06
Monitoring and Vulnerability Management
Model Monster participates in OpenAI's Daybreak program. We maintain continuous security monitoring and a documented vulnerability-management program across the hosted service.
Current practices include:
- Continuous host and service monitoring
- File-integrity and configuration monitoring
- Dependency and container vulnerability scanning
- Hardened deployment images
- Regular agent-based security and penetration testing against production-equivalent environments
- Security-event logging and alert review
- Documented incident triage and remediation
Monitoring, scanning, security reviews, and agent-based testing feed a documented process for triage, tracking, and remediation.
-
06 / 06
Operational Commitments
Documented processes govern incident response, data retention and deletion, backup and recovery, vulnerability management, and change management.
Additional security and diligence information is available on request.
Repository access stays in your environment
Model Monster's MCP workflow keeps repository access inside the customer's environment.
Uploaded architecture evidence is treated as sensitive customer data. Modeled components, integrations, data flows, and risk context can reveal important system information even without source code.
The workflow preserves customer control and minimizes transmitted data. Model Monster's MCP server does not clone or browse customer repositories.
Inspect locally
Preview before applying
Validate the payload
Evaluate and review
Repository access and processing by the customer's agent or model provider remain governed by the customer's configuration and provider agreement.
Engineering, security, legal, and governance teams gain a shared technical evidence layer without granting Model Monster unrestricted access to source code.
Contact
Security questions or diligence requests?
Security questions and diligence requests can be sent to:
We welcome responsible disclosure of suspected vulnerabilities. Please avoid accessing customer data, disrupting service, or exploiting an issue beyond what is necessary to demonstrate it.
Model Monster makes AI governance concrete and reviewable. We apply the same standard to our security: clear controls, clear boundaries, and evidence for the controls we operate.