Honesty statement

Pricemonk is an EU-based SaaS operated by TopMonks s.r.o., which holds ISO/IEC 27001:2022 certification (certificate TDS 54/2025, valid through 1 July 2028; scope explicitly covers pricing solutions). Below is what is in production today, what is on the roadmap, and what you can ask for during a pilot. Anything labelled roadmap is a planning target, not a shipped feature. If a control your security team requires is not on this page, raise it during discovery — we can usually accommodate it inside the pilot contract or honestly tell you when it ships.

Where your data lives

  • EU-based processing and storage. The Pricemonk-hosted product runs on EU infrastructure with EU-only data residency by default. Data does not leave the EEA without prior, written customer consent.
  • Customer-hosted option. If your security posture requires it, we deploy Pricemonk as a containerised standalone inside your own AWS, Azure, GCP, or on-prem environment. Your cloud, your encryption keys, your control. Documented runbook is on the roadmap (target Q3 2026); the deployment artifact is shipping today.

Encryption

  • In transit. All client–server communication uses TLS 1.2 or higher. Authentication cookies are flagged Secure and HttpOnly; HTTPS is enforced at the edge of the Pricemonk-hosted offering.
  • At rest. Customer data is encrypted at the storage layer using the cloud provider's managed KMS in the EU region. Field-level (column-level) encryption for sensitive columns is on the roadmap — target Q3 2026.
  • Keys. Hosted: managed by the cloud provider's KMS with rotation per provider default. Customer-hosted: you own all key material end-to-end.

Identity and access

  • Authentication. Username and password, backed by short-lived JWT access tokens with refresh-token rotation.
  • Single sign-on (SAML 2.0 / OIDC). Roadmap — target Q4 2026. Customers who need SSO before then can deploy Pricemonk behind an IdP-fronted reverse proxy; we support that pattern in pilot.
  • Multi-factor authentication. Application-level TOTP MFA is on the roadmap — target Q3 2026. Until then, customers requiring MFA enforce it at their SSO or IdP layer.
  • Role-based access control. Yes. Pricemonk supports role-based permissions and segregation-of-duties patterns (the proposer of a price change cannot be the approver). The exact role catalogue is confirmed during onboarding for your team structure.

Audit logging

Every change to a price list, every approval action (propose, approve, reject, publish), every login and every role change is logged with the actor, the timestamp, and the prior and new value. Application-level audit logs are append-only. Database-level WORM immutability and a SIEM-export API are on the roadmap — target Q4 2026. For customers who need an external attestation surface today, we offer a daily signed export of audit records to a customer-controlled S3 bucket.

Attestations and compliance

  • ISO/IEC 27001:2022. Pricemonk is operated by TopMonks s.r.o., which holds ISO/IEC 27001:2022 certification under certificate TDS 54/2025, issued 02 July 2025 by TDS Brno (certification body #3105, accredited by the Czech Accreditation Institute under ISO/IEC 17021-1:2015 as IAF MLA member), valid through 1 July 2028. The Statement of Applicability is version 1.0 (30 April 2025). The certificate's scope explicitly covers pricing solutions. The certificate is available on request via security@pricemonk.io.
  • SOC 2. A gap analysis is the parallel track. We do not currently hold a SOC 2 Type 1 or Type 2 report. Customers requiring SOC 2 before our target window should raise it during contracting; we offer a written security-controls statement and a bridge letter in lieu.
  • GDPR. Pricemonk operates within the EU as a data Processor. A GDPR-compliant Data Processing Agreement (DPA) is signed alongside the Master Services Agreement and includes Standard Contractual Clauses where applicable. The DPA is available on request via security@pricemonk.io.
  • PCI DSS. Out of scope. We do not handle cardholder data.
  • External penetration test. On the roadmap — target Q4 2026, conducted by an EU-based testing vendor. Until then, we run internal review and dependency-vulnerability scanning, and we will share scope and findings of any commissioned testing on request under NDA.

Sub-processors and data sharing

Pricemonk maintains a current sub-processor list (hosting, monitoring, support tooling). It is provided to customers at contract signing and on request via security@pricemonk.io. Customers are notified in writing thirty days before a new sub-processor is added, with a right to object.

Data isolation

Customer instances are logically segregated. Single-tenant deployments are offered for customers requiring stricter isolation; this is the default for pilots. Multi-tenant shared-deployment architecture is described per-customer during onboarding.

No lock-in

Your data is yours. Export of price lists, audit history, and configuration is available on request and is contractually preserved at termination. If you have chosen the customer-hosted deployment, there is no Pricemonk-side data store to extract from in the first place.

Reporting a vulnerability

If you believe you have found a security issue in Pricemonk, please email security@pricemonk.io. We acknowledge reports within two business days and aim to remediate in line with severity. We do not currently operate a public bug bounty.

Last updated

2026-06-09 · Next scheduled refresh: at the close of each ISO 27001 surveillance audit, or sooner on material change.