Montro

Trust & Security

You're giving us visibility into everything.

Montro connects to your identity provider, email metadata, and browser activity to name a few and discovers every application your organisation uses. That's a significant trust relationship. This document tells you precisely what we access, where it lives, and what controls govern it.

Trust

Three pillars of security

How we protect your data

Residency

Residency

Customer data stays in Europe

Hosted on AWS eu-central-1 Frankfurt, no external transfers

Learn more
Architecture

Architecture

Built on enterprise primitives

TLS 1.3, AES-256, RBAC, MFA, audit logging throughout

Learn more
Certifications

Certifications

Certification programme in process

SOC 2 Type II Q4 2026, ISO 27001 2027

Learn more

DATA RESIDENCY

European data. Staying in Europe.

All data processed and stored by Montro remains within the European Union. This is not a configuration option or a paid add-on. It is the architecture.

Our infrastructure runs on AWS eu-central-1 Frankfurt, operating under German and EU law.There is no Schrems II ambiguity to navigate.

AWS Frankfurt

AWS - Frankfurt, Germany

Compute, database, and storage infrastructure. Governed by German and EU law.

European by default

European by default

Your data is never replicated outside the EU without your explicit, documented consent.

DPA specifies residency

DPA specifies residency

Data residency terms are included in all Data Processing Agreements - not buried in privacy policies.

EU-located or approved

EU-located or approved

All sub-processors are in the EU or operate under a valid transfer mechanism.

Data Access

Exactly what we access - and exactly what we don't.

Montro's discovery layer operates through three integration vectors. Below is a precise breakdown of what each accesses and what it deliberately does not.

SSO/Identity Provider

Okta, Azure AD, Google Workspace, Microsoft Entra ID

Browser Extension

Chrome / Edge - employee-installed, optional

Email Metadata Analysis

Gmail, Microsoft 365 - metadata only, never message content

Financial / Expense Data

Where connected - optional integration

Security Architecture

How we secure what you share with us

Security is built into Montro's infrastructure, not applied on top of it. Below are the specific controls governing your data at rest and in motion.

01

TLS 1.3

Encryption in transit

All data moving between your environment and Montro's infrastructure is encrypted via TLS 1.3. Older protocol versions are rejected.

02

AES-256

Encryption at rest

All customer data stored in Montro's infrastructure is encrypted at rest using AES-256. Key management follows AWS KMS best practices with strict access controls.

03

Strict data segregation

Tenant Isolation

All customer data is scoped to organisation identifiers enforced at the application and database layers. Cross-tenant access is architecturally prevented.

04

Role-based (RBAC)

Access Controls

Granular permissions govern which users in your organisation see which data. Administrative access is separately scoped and tied to identity - not shared credentials.

05

Read-only by default

Least Privilege

All OAuth scopes requested during integration are the minimum required for discovery. We request read-only access wherever technically possible.

06

Every access event logged

Audit logging

All access events, configuration changes, and administrative actions are logged with timestamps. Logs available to account administrators on request.

07

MFA enforced

Authentication

Multi-factor authentication is enforced for all Montro team members with production access. SSO-based access available for customer admin accounts.

08

VPC isolation

Network security

Production infrastructure runs inside an AWS Virtual Private Cloud with strict ingress and egress controls. No unnecessary public surface area.

GDPR data flow mapping dashboard showing subject, controller, processor, and sub-processor chains

GDPR & PRIVACY

Your data. Your rights. Our obligations.

Under GDPR, Montro acts as a data processor on your behalf. You remain the data controller. Your GDPR obligations don't change because you use Montro - they become easier to fulfil.

Your Organization

You determine the purposes and means of processing personal data. GDPR obligations - lawful basis, data subject rights, breach notification - sit with you.

Montro

We process personal data only on your documented instructions, only for delivering the Montro service, and only for as long as your agreement runs.

Our Own Governance

“Govern every app. Control every AI.” - including our own

Montro exists to solve the shadow AI governance problem. We apply that standard to ourselves - without exception.

  • Every SaaS and AI tool our team uses is classified in Montro's own discovery dashboard
  • Our AI tools - including the LLMs we use in our product pipeline, are classified against EU AI Act risk tiers
  • We maintain our own Record of Processing Activities (RoPA) under GDPR Article 30
  • Shadow AI tools discovered internally are subject to the same governance workflows we recommend to customers
  • Our Montro dashboard is available for review by design partners and prospects as part of our sales process

Certifications and Roadmap

What we have - and what we're building toward

GDPR-Compliant Data Processing

Documented DPA, sub-processor register, retention schedules, breach response procedure, and data subject rights handling - included in all agreements.

AWS Standard Security Controls

Encryption at rest and in transit, VPC network isolation, IAM access controls, CloudTrail audit logging, and automated backup - all active in production.

Internal Security Policy Documentation

Access control policy, incident response procedure, acceptable use policy, and change management controls. Available on request for vendor security questionnaires.

Third-Party Penetration Test

Scheduled with an accredited security firm. Target completion: Q2 2026. Results available under NDA to customers with a signed security questionnaire.

SOC 2 Type II Audit

Auditor engaged. Observation period begins Q2 2026. Target report: Q4 2026. In the interim, we operate to SOC 2 controls and provide our control documentation under NDA on request. Final report shared under NDA with enterprise customers.

ISO 27001 Certification

Target: 2027. Our internal security programme is structured to align with ISO 27001 from the outset.

Annual Third-Party Penetration Testing

Once our initial pen test is complete, annual testing by an accredited firm will become part of our standard security programme.

Sub Processor

Who we share your data with

We use a limited number of third-party sub-processors. All are within the EU or operate under a valid GDPR transfer mechanism. We notify customers with 30 days advance notice of any material changes.

Amazon Web Services (AWS)

Purpose
Primary infrastructure - compute, database (RDS), storage, networking
Data Location
EU (Frankfurt)
Legal Mechanism
Standard Contractual Clauses + AWS DPA

HubSpot

Purpose
CRM and communication metadata - used for customer onboarding and support contacts only
Data Location
Legal Mechanism
Legal Mechanism
Standard Contractual Clauses + HubSpot DPA

Stripe

Purpose
Billing and payment processing - handles payment data; does not process operational customer data
Data Location
EU
Legal Mechanism
Standard Contractual Clauses + Stripe DPA

Found a Vulnerability? Tell Us

If you discover a security vulnerability in Montro, please report it responsibly before public disclosure. We take all reports seriously and commit to responding quickly.

Our commitments to security researchers

  1. We acknowledge receipt of your report within 24 hours
  2. We investigate and respond with a timeline within 5 business days
  3. We keep you informed of remediation progress throughout
  4. We will not take legal action against good-faith security researchers who follow this process

Note : Please do not access or modify customer data, interrupt services, or perform social engineering as part of your research. Allow us reasonable time to remediate before any public disclosure.

Send vulnerability reports

to [email protected]. Please include a description of the vulnerability, steps to reproduce, and potential impact. PGP encryption is available on request.

Contact

Talk to us directly

Have a security questionnaire to complete? Need documentation for your DPO? Want to discuss our architecture before committing to a trial? We respond directly - not through a ticketing system.

Security

Vendor security questionnaires, pen test documentation, architecture questions, vulnerability reports

[email protected]

Privacy & GDPR

DPA requests, sub-processor lists, data subject rights queries, GDPR documentation

[email protected]