Security and compliance
Security and compliance How MonoChat protects customer conversations
Customer conversations hold personal data, so access to them has to be deliberate. This page summarises the certifications, product controls and data-handling practices behind MonoChat, and where to ask for more detail.
Or start with $150 of credit, enough for a first month of Growth
- ISO 27001
- Information security
- Information security management certification
- ISO 9001
- Quality management
- Quality management certification
- Meta
- Business Partner
- Official WhatsApp, Instagram and Messenger APIs
- KVKK
- Data protection law
- Privacy policy prepared under Law No. 6698
Access and control features in the product
The controls teams use every day to decide who can see and do what in a workspace.
-
Role-based access
Assign roles and permissions so agents, supervisors and admins only reach the conversations and settings they need.
Learn more -
Workspace isolation
Each workspace keeps its own channels, contacts, assistants and credentials, separate from other workspaces.
-
Audit logs
Conversation history and logged actions show who did what, so changes and handovers can be reviewed later.
Learn more -
Protected credentials
Provider credentials, such as your LLM and vector database keys, are stored encrypted and scoped to your workspace.
Learn more -
Official channel APIs
WhatsApp is connected through the official WhatsApp Business Platform (Cloud API), not through unofficial automation of the consumer app.
Learn more -
Controlled AI actions
AI tools run with validation, permissions, allowlisted endpoints and logs, so an assistant can only do what you allow.
Learn more
You choose where AI and data live
MonoChat is built so sensitive parts of the stack can stay under your control.
-
Bring your own LLM keys
Connect your own OpenAI, Anthropic, Google, Azure, AWS or other provider account, and decide which assistant uses which model.
Learn more -
Self-hosted models
Connect self-hosted models through Ollama or your own model API when prompts should stay on your infrastructure.
Learn more -
Your own vector database
Keep knowledge-base vectors in the vector database you choose, with your own storage and retention policies.
Learn more -
On-premise deployment
The Enterprise plan offers on-prem deployment, a custom SLA and a dedicated account manager for stricter requirements.
Learn more
Privacy and data handling
The privacy policy is the binding text. In short, it commits MonoChat to the following.
- Personal data is processed under the Turkish Personal Data Protection Law No. 6698 (KVKK), by Bordo Bilişim Ticaret A.Ş. as data controller.
- Security policies compliant with ISO 27001 standards, with regular security audits and updates.
- Multi-factor authentication against unauthorized access, plus data backup and recovery systems.
- Data is shared only with the channel and infrastructure providers needed to deliver the service, with authorities where the law requires, or with your explicit consent.
- You can ask to access, correct or delete your personal data; requests are answered within 30 days.
Cookie consent on this website
monochat.ai uses a consent banner connected to Google Consent Mode v2. Analytics and advertising storage stay denied until you choose, rejecting is one click, and you can change your choice at any time from “Cookie settings” in the footer.
Policies and legal documents
Report a vulnerability or ask our security team
Found something that looks like a security issue, or need answers for a vendor assessment? Write to us with as much detail as you can share. Please do not include customer data or credentials in the message.
For security questionnaires and Enterprise reviews, mention your company and timeline so we can route the request.
FAQ
Security and compliance questions
Straight answers on what MonoChat does and does not claim.
Is MonoChat ISO 27001 certified?
Yes. MonoChat holds ISO 27001 (information security management) and ISO 9001 (quality management) certifications. Contact us at hello@monochat.ai if you need the certificates for a vendor review.
Does MonoChat use the official WhatsApp API?
Yes. WhatsApp is connected through the official WhatsApp Business Platform (Cloud API), and MonoChat carries the Meta Business Partner badge. Instagram and Messenger are connected through Meta’s official APIs as well.
Can I control which AI provider processes my conversations?
Yes. You can bring your own keys for providers such as OpenAI, Anthropic and Google, connect self-hosted models through Ollama or a custom API, and choose which assistant uses which model. MonoChat adds no markup when you use your own keys.
Who can see customer conversations inside my workspace?
Only the users you invite, according to the roles and permissions you assign. Workgroups and routing rules decide which team handles which conversations, and conversation history shows who handled each one.
Can MonoChat be deployed on our own infrastructure?
On-prem deployment is available on the Enterprise plan, together with a custom SLA and enterprise rollout support. Talk to our team to scope it.
How do I request deletion of my personal data?
Send a request to hello@monochat.ai. Under the privacy policy, requests to access, correct or delete personal data are reviewed and answered within 30 days.
Keep exploring
-
About MonoChat
Who builds MonoChat and what we are working towards. -
Contact
Talk to sales or support on WhatsApp, e-mail or phone. -
Partnership Program
Join the MonoChat partner program and earn recurring revenue. -
Partner Directory
Explore certified MonoChat agencies, integrators and solution partners.
First month of Growth on us
Need details for a security review?
Start on the free plan to evaluate the product, or message us and we will answer your security and compliance questions.
One code per business • 30 days to redeem • No card needed