Security at Pricemonk
Your pricing data is some of the most commercially sensitive data in your business. Here is what we do, what we don't yet do, and how we'll tell you about the difference.
Honesty statement
Pricemonk is an EU-based SaaS operated by TopMonks s.r.o., which holds ISO/IEC 27001:2022 certification (certificate TDS 54/2025, valid through 1 July 2028; scope explicitly covers pricing solutions). Below is what is in production today, what is on the roadmap, and what you can ask for during a pilot. Anything labelled roadmap is a planning target, not a shipped feature. If a control your security team requires is not on this page, raise it during discovery — we can usually accommodate it inside the pilot contract or honestly tell you when it ships.
Where your data lives
- EU-based processing and storage. The Pricemonk-hosted product runs on EU infrastructure with EU-only data residency by default. Data does not leave the EEA without prior, written customer consent.
- Customer-hosted option. If your security posture requires it, we deploy Pricemonk as a containerised standalone inside your own AWS, Azure, GCP, or on-prem environment. Your cloud, your encryption keys, your control. Documented runbook is on the roadmap (target Q3 2026); the deployment artifact is shipping today.
Encryption
- In transit. All client–server communication uses TLS 1.2 or higher. Authentication cookies are flagged
SecureandHttpOnly; HTTPS is enforced at the edge of the Pricemonk-hosted offering. - At rest. Customer data is encrypted at the storage layer using the cloud provider's managed KMS in the EU region. Field-level (column-level) encryption for sensitive columns is on the roadmap — target Q3 2026.
- Keys. Hosted: managed by the cloud provider's KMS with rotation per provider default. Customer-hosted: you own all key material end-to-end.
Identity and access
- Authentication. Username and password, backed by short-lived JWT access tokens with refresh-token rotation.
- Single sign-on (SAML 2.0 / OIDC). Roadmap — target Q4 2026. Customers who need SSO before then can deploy Pricemonk behind an IdP-fronted reverse proxy; we support that pattern in pilot.
- Multi-factor authentication. Application-level TOTP MFA is on the roadmap — target Q3 2026. Until then, customers requiring MFA enforce it at their SSO or IdP layer.
- Role-based access control. Yes. Pricemonk supports role-based permissions and segregation-of-duties patterns (the proposer of a price change cannot be the approver). The exact role catalogue is confirmed during onboarding for your team structure.
Audit logging
Every change to a price list, every approval action (propose, approve, reject, publish), every login and every role change is logged with the actor, the timestamp, and the prior and new value. Application-level audit logs are append-only. Database-level WORM immutability and a SIEM-export API are on the roadmap — target Q4 2026. For customers who need an external attestation surface today, we offer a daily signed export of audit records to a customer-controlled S3 bucket.
Attestations and compliance
- ISO/IEC 27001:2022. Pricemonk is operated by TopMonks s.r.o., which holds ISO/IEC 27001:2022 certification under certificate TDS 54/2025, issued 02 July 2025 by TDS Brno (certification body #3105, accredited by the Czech Accreditation Institute under ISO/IEC 17021-1:2015 as IAF MLA member), valid through 1 July 2028. The Statement of Applicability is version 1.0 (30 April 2025). The certificate's scope explicitly covers pricing solutions. The certificate is available on request via security@pricemonk.io.
- SOC 2. A gap analysis is the parallel track. We do not currently hold a SOC 2 Type 1 or Type 2 report. Customers requiring SOC 2 before our target window should raise it during contracting; we offer a written security-controls statement and a bridge letter in lieu.
- GDPR. Pricemonk operates within the EU as a data Processor. A GDPR-compliant Data Processing Agreement (DPA) is signed alongside the Master Services Agreement and includes Standard Contractual Clauses where applicable. The DPA is available on request via security@pricemonk.io.
- PCI DSS. Out of scope. We do not handle cardholder data.
- External penetration test. On the roadmap — target Q4 2026, conducted by an EU-based testing vendor. Until then, we run internal review and dependency-vulnerability scanning, and we will share scope and findings of any commissioned testing on request under NDA.
Sub-processors and data sharing
Pricemonk maintains a current sub-processor list (hosting, monitoring, support tooling). It is provided to customers at contract signing and on request via security@pricemonk.io. Customers are notified in writing thirty days before a new sub-processor is added, with a right to object.
Data isolation
Customer instances are logically segregated. Single-tenant deployments are offered for customers requiring stricter isolation; this is the default for pilots. Multi-tenant shared-deployment architecture is described per-customer during onboarding.
No lock-in
Your data is yours. Export of price lists, audit history, and configuration is available on request and is contractually preserved at termination. If you have chosen the customer-hosted deployment, there is no Pricemonk-side data store to extract from in the first place.
Reporting a vulnerability
If you believe you have found a security issue in Pricemonk, please email security@pricemonk.io. We acknowledge reports within two business days and aim to remediate in line with severity. We do not currently operate a public bug bounty.
Last updated
2026-06-09 · Next scheduled refresh: at the close of each ISO 27001 surveillance audit, or sooner on material change.