Bring your security team into the pilot scope while you choose the workflow. The questions below cover deployment, access, and the evidence available for procurement review.

Deployment and procurement questions

Where can Monarch be hosted, and what does that mean for our data?

Monarch offers AWS hosting in the US, UK, EU, and Australia, or deployment in your own cloud. Customer-cloud hosting is an optional Enterprise add-on. Hosting location alone does not establish where every part of a workflow processes or stores data. Confirm model processing, operational records, backups, and support access for the proposed deployment during the security review.

Can we use models our organisation has already approved?

Yes. Monarch supports your choice of approved models, including major providers, open-source models, and your own models. Confirm the model, endpoint, features, and processing terms when scoping the deployment.

Who controls Monarch's access to our systems?

Your team provisions the service account and scopes its permissions. You can change or revoke that access, and Monarch does not require access to your codebase.

Monarch inherits your role-based access controls and adds action-level controls. Scope the account to the work under review so the pilot tests the permissions you intend to use.

Can we review changes before they happen and inspect them afterwards?

Yes. Proposed creates, updates, and deletes are visible for review before the workflow runs, and a person approves consequential changes.

Monarch logs reads and writes with the system, action, and credentials used, along with what changed. These records let a reviewer inspect the actions behind a completed case.

How long are audit records retained?

The Monarch plans include 30-day audit retention on Launch, 90-day retention on Scale, and custom retention on Enterprise. These periods apply to audit records, not a single retention period for all customer data. Confirm retention and deletion for other data handled by the proposed deployment, including operational records and backups where applicable.

What should we agree before starting a pilot?

Start with a named workflow owner, the systems and records in scope, the account permissions, and the changes that need approval. Agree the deployment, data handling, success criteria, and what happens to access and data at the end. The pricing page describes the 30-day pilot and what is included.

What evidence can our procurement team request?

Customers and prospects can request Monarch's SOC 2 Type II report and penetration test summary under NDA. We can also work with your team on a custom data processing agreement.

Bring the workflow and your deployment requirements to the security review. We can review the proposed access and the supporting reports with your team.