Security
Enterprise security by design, not by add-on.
MonoTeams is built for organizations that treat communication as critical infrastructure. Here is exactly how your data is protected.
- SOC 2 Type II
- GDPR
- ISO 27001
- CCPA
- HIPAA-ready
Encrypted at every layer
Meetings and messages are encrypted in transit and at rest. End-to-end encryption is available for meetings and enforced by policy — when it is on, meeting media is unreadable to anyone outside the call, including us.
- ✓TLS 1.3 in transit, AES-256 at rest
- ✓End-to-end encrypted meetings
- ✓Signed, expiring file URLs
Tenant isolation by architecture
Every record, cache key, realtime event, and media room is scoped to your organization. Isolation is enforced in the data layer and the authorization layer — not by convention. Organizations that need full separation can run MonoTeams as a standalone deployment.
- ✓Tenant scoping on every table and topic
- ✓Dedicated or self-hosted deployment options
- ✓Data residency controls on Enterprise Plus
Identity and access, centralized
Bring your identity provider. Provision and deprovision with SCIM, enforce MFA, claim your domain, and control exactly what guests can see and do.
- ✓SSO with OIDC and SAML
- ✓SCIM provisioning
- ✓Guest policies and waiting rooms
- ✓Session revocation
Governance that leaves a trail
Retention, recording, and export policies are set once and enforced everywhere. Every sensitive action — logins, policy changes, deletions, recording access, guest admissions — lands in an immutable audit log.
- ✓Configurable retention windows
- ✓Compliance holds and exports
- ✓Immutable audit logging