Trust, Security & Compliance
Monic AI Systems measures how government and higher education organizations are represented across public AI systems using a public-information-focused architecture. This page states our security controls, data-handling practices, and compliance roadmap plainly, without overstating certification status.
Security & Compliance Posture
Monic AI Systems is designed for public-information and open-source intelligence use cases. Our standard government offering is not intended to ingest classified information, Controlled Unclassified Information, sensitive government system data, or customer-provided personally identifiable information.
The platform is designed with layered security controls including encrypted communications, encryption at rest, row-level access controls, least-privilege administration, authenticated user access, tenant isolation, and U.S.-based infrastructure configurations where required.
Monic AI Systems is building its independent security assurance program around recognized industry frameworks. SOC 2 Type II readiness activities are underway, ISO/IEC 27001 certification is on the compliance roadmap, and FedRAMP and StateRAMP applicability are being evaluated based on future deployment requirements.
Where Monic AI Systems relies on third-party infrastructure providers with their own SOC 2, ISO 27001, or other security attestations, those certifications apply to the provider's environment and support our broader security architecture. They do not constitute certifications of Monic AI Systems itself.
Public Information by Design
Our standard monitoring service analyzes publicly available information and responses generated from public-facing AI systems. We do not require access to classified systems, internal agency repositories, CUI environments, or sensitive government networks to perform our core AI visibility work.
Customers should not submit classified information, CUI, sensitive personal information, or restricted government data unless a future deployment has been explicitly designed and contractually approved to handle that information.
Security Controls
ImplementedEncryption in transit
Network communications are encrypted using modern TLS protocols.
Encryption at rest
Production databases and storage use encryption at rest through our infrastructure providers.
Tenant isolation
Application and database controls are designed to isolate customer data between client environments.
Row-level security
Database authorization policies restrict access to records based on user and workspace permissions.
Least-privilege access
Administrative access is restricted based on role and operational need.
Authentication
Authenticated sessions, access controls, and enhanced identity capabilities are used to protect customer environments.
U.S. Data Residency
U.S.-based infrastructure configurations are available for government deployments. Hosting location, subprocessors, and data residency requirements can be documented as part of the customer security review and contract.
Compliance Roadmap
Certification status is stated explicitly. Planned or in-progress frameworks should not be interpreted as completed certifications or government authorizations.
SOC 2 Type II
Readiness and implementation underwayMonic AI Systems is implementing controls aligned with the AICPA Trust Services Criteria, including security governance, access management, vendor oversight, change management, incident response, and evidence collection. Independent audit timing will be published once formally engaged.
ISO/IEC 27001:2022
PlannedDevelopment of an information security management system and supporting policies is part of the Monic AI Systems security roadmap. Monic AI Systems is not currently ISO/IEC 27001 certified.
FedRAMP / StateRAMP
Applicability under evaluationMonic AI Systems is evaluating FedRAMP and StateRAMP requirements for future deployments involving government-hosted information, agency systems, or higher-impact workloads. Authorization requirements will depend on the deployment architecture, information processed, agency requirements, and contractual scope.
Infrastructure Assurance
Monic AI Systems uses established cloud and application infrastructure providers with mature security programs. Where those providers maintain SOC 2, ISO/IEC 27001, or similar attestations, those certifications apply to the provider's defined environment. Monic AI Systems incorporates relevant provider controls into its own security architecture and vendor risk management program.
Provider certifications do not represent certification of Monic AI Systems.
AI Data Handling
- Data minimization. Only information necessary to perform the requested analysis should be submitted to AI providers.
- No training by Monic AI Systems. Monic AI Systems does not use customer information to train proprietary foundation models.
- Third-party AI providers. Requests may be processed by third-party AI model providers depending on the selected service configuration.
- Retention controls. Where available, enterprise privacy, data processing, and reduced-retention configurations are used.
- Customer ownership. Customers retain ownership of their source information and deliverables subject to applicable contractual terms.
Incident Response & Security Operations
Monic AI Systems maintains documented processes for identifying, escalating, investigating, and responding to security incidents. Customer notification obligations are governed by applicable law and contractual requirements.
Security monitoring, authentication events, access patterns, and administrative activity may be logged and reviewed based on deployment configuration.
Confidential vulnerability reports: security@monicaisystems.com. Good-faith security researchers will not face legal action for responsible disclosure.
Government Buyer FAQ
Does Monic AI Systems process classified information or CUI?
Our standard offering is not designed to ingest classified information or Controlled Unclassified Information. Customers should not provide such information unless a separately approved deployment has been designed and contractually authorized for that purpose.
Does Monic AI Systems process PII?
Our core AI visibility service is designed to operate without customer-provided sensitive PII. Limited business contact or account information may still be processed for normal authentication, administration, billing, or customer support purposes.
Is FedRAMP authorization required?
FedRAMP applicability depends on the specific agency use case, deployment architecture, information processed, and contract requirements. Because Monic AI Systems' standard AI visibility service is designed around publicly available information rather than federal system data or CUI, some deployments may not require FedRAMP authorization. Agencies should make the final determination based on their security and procurement requirements.
Is Monic AI Systems ISO 27001 certified?
No. ISO/IEC 27001 certification is on the Monic AI Systems compliance roadmap. Current certification status will always be stated explicitly on this page.
Does Monic AI Systems have SOC 2 Type II?
Not yet. SOC 2 controls and readiness activities are underway. Monic AI Systems will update this page when an independent examination has been completed.
Is customer information used to train AI models?
Monic AI Systems does not use customer information to train proprietary foundation models. Third-party AI processing is governed by the provider configuration and applicable contractual and data protection terms.
Can Monic AI Systems complete a vendor security questionnaire?
Yes. Monic AI Systems can participate in customer security reviews and vendor security questionnaires and provide supporting security documentation appropriate to the engagement.
Additional Disclosures
Need documentation for your security review?
Government, higher education, and enterprise buyers can request security architecture information, controls documentation, subprocessor information, data-flow information, or a completed vendor security questionnaire.