> For the complete documentation index, see [llms.txt](https://docs.monolithforensics.com/monolith/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.monolithforensics.com/monolith/deployment-and-security/cloud-security/security-overview.md).

# Security Overview

Review Monolith cloud security architecture, tenant isolation, encryption, backups, vulnerability management, endpoint protection, penetration testing, and logging.

### Multi-Tenancy

All customers are assigned a Monolith **Tenant**. A Tenant is a logical unit that separates each customer's data into its own environment.

In Monolith, each customer has their own database and logical file storage area. This means that data entered into Monolith is not commingled with data from other customers.

The same concept applies to files uploaded into Monolith. Files are stored within logical storage boundaries associated with the customer Tenant.

**Data Export**

This Tenant architecture also makes it straightforward to provide customers with a copy of their Monolith data.

To request a data export, contact <support@monolithforensics.com>.

### Encryption

All data stored in Monolith is encrypted at rest using AES-256 encryption. This includes data stored in databases, server infrastructure, and file object storage.

Data transmitted to, from, or within supported Monolith cloud services is encrypted using HTTPS and TLS encryption standards/protocols.

Encryption is managed by Monolith. A limited number of authorized Monolith personnel may require access to customer data for support and maintenance purposes.

### Security Operations Policy

Monolith maintains internal Security Operations and Data Management policies that define our security and data handling standards in greater detail.

Organizations that need supporting policy documentation for a security review, procurement process, or vendor assessment can contact <support@monolithforensics.com>.

### Cloud Hosting

Monolith cloud infrastructure is hosted in Amazon Web Services (AWS).

Monolith currently operates hosted cloud environments serving customers in:

* **United States / North America**
* **United Kingdom / Europe**
* **Australia**
* **Canada**

Monolith also supports a **United Kingdom / Blue Lights Digital** partner environment.

Our United States cloud environment is hosted in the **AWS GovCloud East Region**.

AWS GovCloud has additional security and compliance controls designed for organizations with regulatory or sensitive workload requirements. More information about AWS GovCloud is available from AWS. [AWS GovCloud Info](https://aws.amazon.com/govcloud-us/?whats-new-ess.sort-by=item.additionalFields.postDateTime\&whats-new-ess.sort-order=desc)

For additional service URLs, regional endpoints, and network allowlisting information, see **Monolith Endpoints**.

## Data Backup

### **Database Backups**

Monolith database data is backed up every 24 hours. We retain up to 30 days of database backups, allowing data to be recovered from previous backup points when necessary.

We may also create manual database backups before major updates or maintenance activities that require database changes.

Backups are stored in an encrypted format separately from the active database environment to support recovery in the event of an infrastructure or regional service disruption.

**File Object Storage Backups**

Files uploaded to Monolith object storage use object versioning.

When a file is overwritten, a new object version can be created while previous versions are retained. This provides additional recovery options for files that are accidentally overwritten or deleted.

Deleted file versions may be retained for up to 90 days.

## Basic Cloud Infrastructure

### Cloud Infrastructure

The following diagram provides a simplified view of the Monolith cloud environment and illustrates how major infrastructure components communicate and share data.

<figure><img src="https://2683670198-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCD1iskOdIm8E2TpCd9iZ%2Fuploads%2FFg90j5QdLETraBmqmMEs%2FMonolith%20Network%20Diagram.png?alt=media&amp;token=a7d68421-07bc-4bf1-8e5b-45bc7e5e3062" alt=""><figcaption></figcaption></figure>

### Vulnerability Scans

The Monolith cloud infrastructure has network and system level scans that occur every 24 hours to test for network and system vulnerabilities.&#x20;

These scans are used to identify vulnerabilities, configuration issues, and other conditions that may fall outside our security baseline. Results can then be reviewed and remediated as appropriate.

### A/V - Malware Detection

All of our endpoints, including employee systems, are monitored using Crowdstrike Falcon.  This provides continuous 24/7 monitoring of our endpoints for threat detection and allows for immediate remediation.

### Penetration Testing

Monolith conducts annual penetration testing to identify common infrastructure vulnerabilities, configuration issues, and application vulnerabilities.

Testing is performed by an independent third party in controlled Monolith environments to avoid unnecessary disruption to customer-facing production services and reduce the risk of exposure to customer data during testing.

Customers may request information about our latest penetration test by contacting <support@monolithforensics.com>.

### Logging

Various system logs are managed using AWS logging services and Datadog.

Supported logs are aggregated within Datadog, providing a centralized location for operational monitoring, investigation, and periodic review.
