Trust Center
Security and Trust
During a project, Monolitica enters the client's operation, maps processes and builds intelligent agents, automations, dashboards, integrations and internal systems from real data, often sensitive (data on residents, employees or industrial processes). This page describes how we protect that data throughout a project, which processors we use and how we respond to incidents.
Last updated: 20 July 2026
Infrastructure
Where the systems run
The systems developed for a client can run on the cloud managed by Monolitica, on the client's cloud, or on-premise. On the managed cloud, data is encrypted and hosted in the European Union. On the client's cloud or on-premise, data remains on infrastructure controlled by the client. In environments managed by Monolitica, we apply segregation between development, staging and production, and restrict access to the project team. On the managed cloud we use Vercel (corporate website), Railway (applications) and Neon (PostgreSQL database), always in European Union regions — Amsterdam and Frankfurt. The full list is on the sub-processors page.
Encryption
Practice adopted in every project - TLS 1.3 in transit (including calls to AI model providers) and AES-256 at rest, whenever data resides on Monolitica's own infrastructure.
Access control
Principle of least privilege - only the project team has access to that client's data. Permissions can be defined in detail by role, team and process, and actions are logged for audit. MFA is mandatory for the whole team. Access to the client's production environments is granted only for the duration of the project and reviewed at the end of each phase.
AI models · privacy
Model choice depends on the project - typically OpenAI or Anthropic(Claude) via API, and sometimes the client's own Microsoft/Google tenant (e.g. Copilot, Gemini) when that reduces data exposure. In the contracts we use as reference, training models on submitted data is disabled by default. When a system is configured to use the client's own API key or tenant, the data is covered by the contract between that client and the provider, not by ours.
List of technical processors, processing country and transfer mechanism at /sub-processadores.
Compliance
- GDPR by default / Law 58/2019. Privacy by design, with a dedicated data protection channel ([email protected]), a record of processing activities per project, a data protection impact assessment (DPIA) when the project involves sensitive data of residents or employees, breach notification to the CNPD (the Portuguese data protection authority) within 72h.
- AI Act (Regulation (EU) 2024/1689), the AI systems we deliver identify themselves as such to citizens, residents or employees who interact directly with them (art. 50), an obligation applicable from 2 August 2026.
- Formal certifications (e.g. ISO 27001, SOC 2) have not yet been obtained. We follow the security practices described on this page in every project, regardless of formal certification.
Incident response
Internal playbook with responsibilities and a notification chain. A data breach is communicated to the affected client as soon as it is detected, within 48h at most (see DPA), and to the CNPD within 72h when applicable.
Responsible vulnerability disclosure
We welcome private, responsible disclosure of vulnerabilities. Send to [email protected] with enough technical detail to reproduce. We triage the report and communicate the remediation plan.
Project continuity
Project artefacts (documentation, code, configurations) are kept with backups and version control. Concrete recovery point and recovery time objectives (RPO / RTO) are defined per project, based on the criticality of the delivered system. By default, systems on the managed cloud have daily backups, 7-day point-in-time recovery (PITR) on the database, and 30-day retention.