MonetizeNow does not run a hosted trust center (no trust., no security., no Vanta/Drata/SafeBase portal was found). What it publishes instead is a single, substantive public Information Security Policy page that states its control environment, encryption, access, SDLC, vulnerability management, continuity and privacy posture. Read the certification claim carefully: the page says "SOC 2 Type II-ALIGNED control environment" and that the SOC 2 Type II summary and penetration-test attestation are "available to customers under NDA" — that is an alignment claim plus a gated report, not a published certificate. Nothing here is independently verifiable from the public surface.
MonetizeNow maintains a public trust center documenting SOC 2 Type II, GDPR, and Independent penetration testing compliance.
generated: '2026-08-13'
method: searched
probe: true
url: https://www.monetizenow.ai/information-security-policy
description: >-
MonetizeNow does not run a hosted trust center (no trust.<domain>, no
security.<domain>, no Vanta/Drata/SafeBase portal was found). What it publishes
instead is a single, substantive public Information Security Policy page that
states its control environment, encryption, access, SDLC, vulnerability
management, continuity and privacy posture. Read the certification claim
carefully: the page says "SOC 2 Type II-ALIGNED control environment" and that
the SOC 2 Type II summary and penetration-test attestation are "available to
customers under NDA" — that is an alignment claim plus a gated report, not a
published certificate. Nothing here is independently verifiable from the public
surface.
certifications:
- name: SOC 2 Type II
status: claimed-aligned
verifiable_publicly: false
detail: >-
"SOC 2 Type II-aligned control environment"; the report summary is offered to
customers under NDA. No certificate, auditor name, report date or audit
period is published.
- name: GDPR
status: claimed
verifiable_publicly: false
detail: >-
Acts as processor; documented DSAR workflow (access, deletion, correction),
sub-processor erasure propagation, 30-day standard completion. A Data
Processing Addendum is published at
https://www.monetizenow.ai/legal/data-processing-addendum.
- name: Independent penetration testing
status: claimed
verifiable_publicly: false
detail: At least annually, with targeted re-tests after remediation; attestation under NDA.
controls:
encryption_at_rest: AES-256 via AWS KMS-managed keys (databases, volumes, object storage, backups, logs), keys segregated by environment with rotation
encryption_in_transit: TLS 1.2+ for external and inter-service traffic
secrets_management: AWS Secrets Manager / Parameter Store with least-privilege IAM and audit logging
identity: SSO/SAML with MFA required; RBAC/ABAC least privilege; periodic access reviews; just-in-time privilege elevation
secure_sdlc: peer review, SAST/DAST/SCA, container and image scanning, IaC checks, gated CI/CD
vulnerability_management: time-bound remediation SLAs by severity with re-scan validation
monitoring: centralized logging/alerting across authentication, APIs and infrastructure; 24x7 on-call; documented IR with post-incident review
continuity: multi-AZ, multi-region with automated backups and replication; defined RTO/RPO for Tier 1 services; annual DR exercises
endpoint: third-party MDM, full-disk encryption, EDR, screen-lock, patch baselines
hosting: AWS (physical data center controls governed by AWS); network segmentation, security groups, WAF
related_documents:
- {name: Data Processing Addendum, url: 'https://www.monetizenow.ai/legal/data-processing-addendum'}
- {name: Master Services Agreement, url: 'https://www.monetizenow.ai/msa'}
- {name: Privacy Policy, url: 'https://www.monetizenow.ai/privacy-policy'}
- {name: Terms of Use, url: 'https://www.monetizenow.ai/terms-of-use'}
evidence:
- source: https://www.monetizenow.ai/information-security-policy
http_status: 200
fetched: '2026-08-13'
keywords: [soc 2 type ii, gdpr, penetration testing, aes-256, aws kms, dsar, rto, rpo, sub-processor]
last_updated_by_provider: '2024-09-24'
notes:
- >-
A named certifications list is published, so a Compliance pointer is emitted —
but the qualifier "aligned" is deliberately preserved above. Do not restate this
as "SOC 2 certified".
- >-
No sub-processor list, no uptime SLA and no audit report date are published.
status.monetizeplatform.com carries live status but no SLA target.
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.