Essential cookies keep you signed in; analytics only with your consent. See our Privacy Policy
Multi-tenant isolation. Encryption at rest. Bcrypt-hashed passwords. TLS 1.2+ with HSTS. Strict CSP. HMAC-signed unsubscribe. Every claim on this page is grounded in the production code — not aspirational marketing
Every customer signed up to Monqez AI gets a logically isolated slice of the system. Concretely:
user_id. Backend queries always include this filter — there is no path in the API that returns another tenant's datamonqezai.io is served over TLS 1.2+ with HSTS enforced for one year, which means browsers refuse to downgrade to HTTPWe score grade A on securityheaders.com thanks to:
includeSubDomainsframe-ancestors 'none' to block clickjackingWe take security reports seriously and respond within 48 hours. Our disclosure policy lives at /.well-known/security.txt (RFC 9116) — please read it before testing
Yes. Every customer has their own database row, their own knowledge base, and their own integration credentials. Queries are scoped by user_id on every read and write. We never share data across tenants and never train shared models on customer conversations
Sensitive fields (integration tokens, SMTP credentials, API keys) are encrypted at rest with AES-256-GCM using a key held in a server-side environment variable — never in our code or version control. All traffic to and from monqezai.io uses TLS 1.2+ with HSTS enforced for one year
Passwords are hashed with bcrypt at cost factor 12. Plain-text passwords are never logged, never stored, and never sent in emails — including password resets, which use a one-time token instead
No. Card details never reach our servers. Plan purchases run through Stripe Checkout, where you pay on a page hosted by Stripe, and when you save a card in the dashboard the input fields are rendered by Stripe inside their own iframe — the details go straight from your browser to Stripe. We store only a Stripe token plus the last four digits, the card brand and the expiry date, which is what lets the dashboard show you "Visa ending 4242". The full card number is never stored, and the security code (CVV) is never stored or transmitted by us at all. Stripe is certified PCI DSS Level 1, the highest level the standard defines, and every payment confirmation Stripe sends us is signature-verified before we act on it
Every outbound Sales email carries an HMAC-signed unsubscribe link, and opt-outs are enforced before any future send — including across campaigns — which helps you meet requirements like CAN-SPAM. You send from your own mailbox and stay the data controller for your outreach, so compliance with the laws that apply to you (e.g. GDPR and local marketing rules) remains your responsibility — we provide the tools, not a legal guarantee
On a dedicated VPS in the EU (Frankfurt region). Backups are encrypted. We use self-hosted infrastructure — your data is not on a hyperscale cloud unless you explicitly connect one via an integration
Email support@monqezai.io or fetch https://monqezai.io/.well-known/security.txt for our disclosure policy. We respond within 48 hours
Any other questions about how we handle your data? Email us and we’ll answer