Your licensing data powers your business. We take its protection seriously โ from encryption at every layer to tenant isolation in every query. Here's how we keep your data safe.
Encryption
Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
Data in Transit
All API communication is encrypted via TLS 1.2+. HTTPS is enforced on every endpoint โ no plaintext connections are accepted.
Data at Rest
Azure Cosmos DB provides automatic encryption at rest using Microsoft-managed keys (AES-256). Your data is encrypted before it hits disk.
License Keys
License signatures use RSA cryptographic signing for offline verification. Keys are generated server-side and never exposed in plaintext.
Infrastructure
Built on Microsoft Azure with enterprise-grade reliability.
Cloud Platform
Hosted entirely on Microsoft Azure โ Azure Functions for compute, Azure App Service for the portal, and Azure Cosmos DB for data.
Region
Data is stored in Azure regions with geo-redundancy options. Contact us for specific data residency requirements.
Monitoring
Application Insights provides real-time monitoring, alerting, and diagnostics. We detect and respond to anomalies before they impact you.
Authentication & Access
Industry-standard identity management with strict tenant isolation.
Identity
Microsoft Entra External ID handles identity management with industry-standard OAuth 2.0 and OpenID Connect protocols. No custom authentication code.
API Security
Token-based authentication on every API call. Input validation, parameterized queries, and CORS restrictions protect against common attack vectors.
Tenant Isolation
Each reseller and customer operates in isolated data partitions. Every query is scoped to the calling tenant, so cross-tenant data access is blocked at the data layer.
Data Handling
Clear policies on retention, deletion, and privacy.
Retention
Data is retained while your account is active. Monaiq promises no recovery window after an account closes โ the Privacy Policy governs what happens to data afterwards.
Deletion
Deleting an account permanently deletes its data, including all associated licensing data. Deletion is irreversible.
GDPR
Designed with GDPR principles: data minimization, right to access, and right to deletion. Request your data or its removal at any time.
No Credit Cards
Payments are settled by Stripe. Credit card data never touches Monaiq infrastructure โ Stripe handles every card detail and every payout.
Responsible Disclosure
We value the security research community. If you discover a vulnerability, please report it responsibly via email at security@monaiq.com. We'll acknowledge your report and work with you to resolve the issue.