Trust & reliability
Certifications (SOC 2, ISO 27001) are in progress. Here's what's already in place: locked periods, full provenance, and connectors into the Xero or Sage you already run — never a second system of record.
Underway
SOC 2 & ISO 27001
Pursuing formal certification — not claiming it before we've earned it.
TLS
ENCRYPTION IN TRANSIT
Live today. Encryption at rest is on the roadmap as the platform matures.
Single region
DEPLOYMENT FOOTPRINT
One shared environment today; regional isolation is a roadmap item, not a promise with a date.
Xero · Sage
YOUR OWN CONNECTORS
monoclose never becomes a second system of record.
One review path
Routine, low-risk items — bank charges, matched reconciliations inside tolerance — are completed automatically, with evidence attached. Anything above your materiality threshold, or below the agent's confidence threshold, is routed to a reviewer for approval. You set the thresholds per client and per account, and every action can be traced back to its source.
01
monoclose reads from the Xero or Sage you already run over the same connectors you'd use anywhere else. Where a connection needs file storage instead of an ERP feed, it requests the narrowest scope that works — Google Drive's connector uses drive.file, not access to your whole account.
02
Agents reconcile accounts and post journals with the source, balance, and reasoning behind each line recorded as they go — the working paper shows the logic, not just the final number.
03
Routine, low-risk items — bank charges, matched reconciliations inside tolerance — complete automatically, with evidence attached. Anything above your materiality threshold, or below the agent's confidence threshold, is routed to a reviewer for approval. You set the thresholds per client and per account.
Security & deployment
Security baseline
A closed period rejects silent edits outright — a signed-off number never quietly changes underneath you.
Every agent action records what it looked at and why, on every line — not just a final balance.
monoclose reads from the Xero or Sage you already run. It doesn't become a second system of record.
Connections request only the scope the job needs — a file-storage connector asks for the files it manages, never your whole account.
Connector tokens are versioned and rotated, not left as a single static key indefinitely.
A small item handled with total certainty and a large one handled with real doubt are never treated as the same problem.
Single sign-on for enterprise access control is on the roadmap — access is managed per-user today.
Deployment
TODAY
Multi-tenant, shared infrastructure — how every client runs on monoclose right now.
PLANNED
PlannedA dedicated, single-tenant environment for firms that need stronger isolation.
PLANNED
PlannedRunning monoclose inside your own infrastructure — a longer-term direction, not a near-term build.
Certification roadmap
None of these are held yet — we're building the underlying controls first, then pursuing formal certification, rather than the other way around. This is specifically what "underway" means.
An independent audit of the controls that actually run monoclose day to day — not a one-time checklist, an ongoing one.
A recognized standard for how we manage information security as a whole system, not just individual controls.
South Africa's own data protection law — the one that actually governs the client data running through monoclose, not a borrowed overseas equivalent.
The newer standard for how AI systems specifically are governed — relevant to monoclose in a way most close software doesn't have to think about yet.
We're happy to walk your security or compliance team through the architecture directly — locked periods, provenance, connector scopes, all of it.