Security & Trust Center

SOC 2 & Compliance Standards  ·  Last updated: August 23, 2026

Month's End is engineered from day one to uphold the highest enterprise security, confidentiality, and data integrity standards across the entire reporting lifecycle.

1. SOC 2 Trust Services Criteria Alignment

Our infrastructure and development practices adhere strictly to the five AICPA SOC 2 Trust Services Criteria:

2. Cryptographic Architecture & Key Management

3. Least-Privilege API Architecture

We believe in absolute data minimization. Month's End never requests administrative or write access to your analytics or search data:

4. Subprocessor Governance

We work exclusively with SOC 2 / ISO 27001 certified global cloud providers:

5. Responsible Vulnerability Disclosure

We welcome reports from independent security researchers. If you identify a potential security issue, please contact our security team directly with a 24-hour response SLA:

Month's End Security Operations
mattmillerb@outlook.com
PGP fingerprint available upon request.