Security & Infrastructure
Last updated: 15 August 2026
Security is an engineering priority at Monecuer. This page describes our current public security posture and operating principles. It deliberately avoids claiming certifications, response guarantees, infrastructure scale or audit results that have not been independently verified.
Secure-by-design development
We aim to reduce unnecessary permissions, protect secrets, validate inputs, use least-privilege access and keep sensitive operations server-side where appropriate.
Managed infrastructure
The Monecuer public website currently uses Cloudflare infrastructure for hosting, network delivery, DNS and security controls. Product infrastructure may differ by product and environment.
Review and monitoring
We use code review, dependency checks, logs and platform monitoring as appropriate to the system being operated. Response targets are defined per service or incident rather than advertised as universal guarantees.
Data minimisation
Public website forms collect only the information required to respond to inquiries, manage subscriptions and operate the service. Security features are designed around minimising unnecessary data exposure.
Public website protections
- HTTPS delivery and Cloudflare network protections.
- Server-side handling of Resend API keys and other production secrets.
- Rate limiting and validation on public inquiry and newsletter endpoints.
- Spam-resistant form patterns such as honeypot fields where implemented.
- Production builds that exclude internal visual-editing and browser-log instrumentation.
Product security
Individual Monecuer products can use different security controls depending on their architecture and threat model. Product pages may describe specific controls that are implemented in that product. Those descriptions should not be interpreted as company-wide certification.
Compliance references
Monecuer may design systems with customer requirements or recognised frameworks in mind. References to standards such as ISO 27001, SOC 2, PCI DSS, GDPR or similar frameworks describe requirements or engineering references unless Monecuer expressly states that a named organisation or service holds a current third-party certification.
Responsible disclosure
Found a security issue?
Please report it privately to security@monecuer.com. Include enough detail to reproduce the problem, avoid accessing data that is not yours, and give us a reasonable opportunity to investigate before public disclosure.
Incident handling
When a material security issue is identified, our goal is to assess scope, contain the issue, preserve relevant evidence, remediate the root cause and communicate with affected parties when appropriate or legally required. Exact response times depend on severity, system and available information.
Contact
Security: security@monecuer.com
Support: support@monecuer.com
