Security
How we secure the platform itself. A security company should be open about this.
Where your data lives
On servers within the European Union, with European parties, under a data processing agreement. No American hyperscaler.
Access
Access to customer environments is role-based and recorded in an audit log. Staff use multi-factor authentication; there are no shared accounts.
Evidence files
Uploaded evidence files are stored under a content-based key, a fixed mime allowlist and a 25 MB limit per file. Every evidence file gets an audit-log entry.
AI processing
The AI baseline assessment runs on EU infrastructure with no retention of your documents. Every AI draft is reviewed by a human before it enters the file.
Found a vulnerability?
Email contact@munitor.nl. A reply within one working day, no legal action against a good-faith report: see the responsible-disclosure page.