Privacy and Security

Please see our privacy policy for more information.

When reviewing the landscape around financial apps, we noticed a troubling trend — companies making money by selling your financial data, serving ads, and making you the product. We think this is a bad idea - and this deep respect for privacy is a major reason we started Monarch. We are committed to being as transparent as possible about what data we collect and why.

Monarch never stores the user names or passwords to your accounts - this data all flows through our secure third-party data provider partners. Monarch can not move money in or out of your accounts.

Monarch takes data protection and encryption seriously to ensure the security and privacy of our users. All data is encrypted both at rest and in transit, providing robust protection against unauthorized access during storage and transmission. We have comprehensive identity and access management controls in place, including single sign-on (SSO), two-factor authentication (2FA), and prompt removal of access upon employee separation to mitigate risks associated with unauthorized personnel.

Additionally, regular penetration testing is conducted on our Monarch web application to identify and address potential vulnerabilities. Network controls further safeguard user data by preventing unauthorized access and ensuring compliance with industry best practices. These measures collectively demonstrate Monarch's commitment to maintaining the highest standards of security and reliability.

Data provider partners

The data providers that Monarch uses to connect financial accounts are Plaid, Finicity (owned by Mastercard), and MX. We also use Spinwheel to securely connect to a credit bureau for the bill pay feature. The data providers maintain very strict security practices including encryption, role-based access controls at each layer of their infrastructure, publishing a SOC 2 type 2 report, API traffic control, and one of the strongest bug bounty programs in the industry.

You can learn more details about our partners' security practices here:

Was this article helpful?
83 out of 125 found this helpful