Security & trust

Monotree holds the personal data of your employees on your behalf, so security is part of the product rather than a feature. This page states what is in place today, in the terms your IT department and data protection officer will ask about. The detail lives in the ISAE 3000 report and the data processing agreement, both available on request.

Certifications and assurance

Monotree holds an ISAE 3000 assurance report, Type 1 and Type 2, issued by BDO Denmark. It covers the controls behind hosting, access, change management and incident handling, and is renewed annually. Monotree acts as a data processor for personal data processed on behalf of customers, under a data processing agreement pursuant to Article 28 of the GDPR. An ISO 27001 certification is underway.

A dedicated server for every customer

Each customer runs on a dedicated server with its own database. Customer application data and storage are logically isolated between customers, so one customer's load or configuration cannot affect another.

Data stays in the EU

Servers and backups are hosted with cloud providers in the European Union. Customers operating outside the EU are served from the EU as well. Monotree ApS is a Danish company under Danish and EU law.

Encryption and access

Data is encrypted in transit and at rest. Access inside Monotree follows the principle of least privilege: staff get access to a customer's system only when needed for support or operations, staff access is logged, and security is tested and reviewed on an ongoing basis. Inside your app, a permission structure decides what each employee, manager and editor can see and change.

Anonymous whistleblower channel

Whistleblower forms are anonymous by design. The platform does not record who submitted a report, the anonymity of a report cannot be changed afterwards, and reports reach only the people assigned to that form. The whistleblower channel is designed to support the requirements applicable to internal reporting channels under EU and Danish whistleblower rules, including confidential handling and restricted access to reports.

Data processing agreement and sub-processors

Every customer signs Monotree's standard data processing agreement pursuant to Article 28 of the GDPR. The applicable sub-processors are listed in the agreement, and customers are notified before it changes. Request the agreement, the sub-processor list or the ISAE 3000 report at contact@monotree.com.

Your data stays yours

The content in your app belongs to you. You can export your data in a standard format during the subscription and for 30 days after it ends. Data is subsequently deleted in accordance with the data processing agreement and applicable retention requirements. Employees can exercise their GDPR rights through their employer, who remains the data controller.

Incidents

Should a personal data breach occur, Monotree notifies the affected customers without undue delay, with the information they need to assess and meet their own notification obligations.

Questions

Security questionnaires, vendor assessments and procurement questions go to contact@monotree.com. We answer them ourselves; there is no outsourced first line.

Get your app in a few days.
Let's get in touch!

We love demonstrating our platform. Please don't hesitate to contact us if you're interested.

Book a demo

Fill in your information, and we will contact you within a couple of hours.

Your information is secure with us. Read our Privacy policy for more details.

Thank you!

We will contact you within a couple of hours.