Trust & Security
Montro connects to your identity provider, email metadata, and browser activity to name a few and discovers every application your organisation uses. That's a significant trust relationship. This document tells you precisely what we access, where it lives, and what controls govern it.
Trust
How we protect your data

Residency
Hosted on AWS eu-central-1 Frankfurt, no external transfers

Architecture
TLS 1.3, AES-256, RBAC, MFA, audit logging throughout

Certifications
SOC 2 Type II Q4 2026, ISO 27001 2027
DATA RESIDENCY
All data processed and stored by Montro remains within the European Union. This is not a configuration option or a paid add-on. It is the architecture.
Our infrastructure runs on AWS eu-central-1 Frankfurt, operating under German and EU law.There is no Schrems II ambiguity to navigate.
Compute, database, and storage infrastructure. Governed by German and EU law.
Your data is never replicated outside the EU without your explicit, documented consent.
Data residency terms are included in all Data Processing Agreements - not buried in privacy policies.
All sub-processors are in the EU or operate under a valid transfer mechanism.
Data Access
Montro's discovery layer operates through three integration vectors. Below is a precise breakdown of what each accesses and what it deliberately does not.
SSO/Identity Provider
Okta, Azure AD, Google Workspace, Microsoft Entra ID
Browser Extension
Chrome / Edge - employee-installed, optional
Email Metadata Analysis
Gmail, Microsoft 365 - metadata only, never message content
Financial / Expense Data
Where connected - optional integration
Security Architecture
Security is built into Montro's infrastructure, not applied on top of it. Below are the specific controls governing your data at rest and in motion.
01
TLS 1.3
All data moving between your environment and Montro's infrastructure is encrypted via TLS 1.3. Older protocol versions are rejected.
02
AES-256
All customer data stored in Montro's infrastructure is encrypted at rest using AES-256. Key management follows AWS KMS best practices with strict access controls.
03
Strict data segregation
All customer data is scoped to organisation identifiers enforced at the application and database layers. Cross-tenant access is architecturally prevented.
04
Role-based (RBAC)
Granular permissions govern which users in your organisation see which data. Administrative access is separately scoped and tied to identity - not shared credentials.
05
Read-only by default
All OAuth scopes requested during integration are the minimum required for discovery. We request read-only access wherever technically possible.
06
Every access event logged
All access events, configuration changes, and administrative actions are logged with timestamps. Logs available to account administrators on request.
07
MFA enforced
Multi-factor authentication is enforced for all Montro team members with production access. SSO-based access available for customer admin accounts.
08
VPC isolation
Production infrastructure runs inside an AWS Virtual Private Cloud with strict ingress and egress controls. No unnecessary public surface area.

GDPR & PRIVACY
Under GDPR, Montro acts as a data processor on your behalf. You remain the data controller. Your GDPR obligations don't change because you use Montro - they become easier to fulfil.
You determine the purposes and means of processing personal data. GDPR obligations - lawful basis, data subject rights, breach notification - sit with you.
We process personal data only on your documented instructions, only for delivering the Montro service, and only for as long as your agreement runs.
Our Own Governance
Montro exists to solve the shadow AI governance problem. We apply that standard to ourselves - without exception.
Certifications and Roadmap
Documented DPA, sub-processor register, retention schedules, breach response procedure, and data subject rights handling - included in all agreements.
Encryption at rest and in transit, VPC network isolation, IAM access controls, CloudTrail audit logging, and automated backup - all active in production.
Access control policy, incident response procedure, acceptable use policy, and change management controls. Available on request for vendor security questionnaires.
Scheduled with an accredited security firm. Target completion: Q2 2026. Results available under NDA to customers with a signed security questionnaire.
Auditor engaged. Observation period begins Q2 2026. Target report: Q4 2026. In the interim, we operate to SOC 2 controls and provide our control documentation under NDA on request. Final report shared under NDA with enterprise customers.
Target: 2027. Our internal security programme is structured to align with ISO 27001 from the outset.
Once our initial pen test is complete, annual testing by an accredited firm will become part of our standard security programme.
Sub Processor
We use a limited number of third-party sub-processors. All are within the EU or operate under a valid GDPR transfer mechanism. We notify customers with 30 days advance notice of any material changes.
| Sub-Processor | Purpose | Data Location | Legal Mechanism |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary infrastructure - compute, database (RDS), storage, networking | EU (Frankfurt) | Standard Contractual Clauses + AWS DPA |
| HubSpot | CRM and communication metadata - used for customer onboarding and support contacts only | Legal Mechanism | Standard Contractual Clauses + HubSpot DPA |
| Stripe | Billing and payment processing - handles payment data; does not process operational customer data | EU | Standard Contractual Clauses + Stripe DPA |
Amazon Web Services (AWS)
HubSpot
Stripe
If you discover a security vulnerability in Montro, please report it responsibly before public disclosure. We take all reports seriously and commit to responding quickly.
Our commitments to security researchers
Note : Please do not access or modify customer data, interrupt services, or perform social engineering as part of your research. Allow us reasonable time to remediate before any public disclosure.
to [email protected]. Please include a description of the vulnerability, steps to reproduce, and potential impact. PGP encryption is available on request.
Contact
Have a security questionnaire to complete? Need documentation for your DPO? Want to discuss our architecture before committing to a trial? We respond directly - not through a ticketing system.
Vendor security questionnaires, pen test documentation, architecture questions, vulnerability reports
DPA requests, sub-processor lists, data subject rights queries, GDPR documentation