Monverdo · Security and data
What happens to your data
Monverdo is still in development. This page describes what is true today, which is a website, ten calculators and a waitlist. It is equally explicit about what has not been built, because a security page describing a system that does not yet exist is worth nothing.
The calculators run in your browser
Nothing you type into a calculator is sent to Monverdo.
The ten calculators run entirely on your own device. Your figures are held in the browser tab whilst you work and are discarded when you close it. There is no account, no login and no saved copy held by Monverdo. If you print or export a result, that file is produced on your machine.
This is a deliberate design decision rather than a limitation. You should be able to put real figures into a calculator without first handing them to a company you have never dealt with.
Results are never withheld behind an email address. You do not pay for a calculation with your contact details.
What the waitlist stores
If you request early access, Monverdo stores your email address and the record of your consent. That is the entire record.
Your email address, the date you gave consent, plus which page you came from. No name is required, no phone number, no financial information.
Your explicit consent, captured at the point you sign up. Nothing is pre-ticked. Declining is as easy as accepting.
Notifying you when early access opens, plus occasional notes on what is being built. Nothing else. Your address is not sold, rented or shared for marketing purposes.
Every email carries an unsubscribe link. You may also request deletion of your address, which will be actioned without your being asked why.
Analytics and cookies
Monverdo uses Google Analytics to count page views and see which pages are read. It sets cookies, so it asks first. Nothing is loaded until you agree through the consent banner, and declining leaves the site entirely usable.
No advertising profile is built and you are not followed to other sites. If you decline, no analytics cookies are set and the only thing recorded is the choice you made.
Third parties
One company holds anything you give Monverdo. That company is Loops.
Loops holds the early-access waitlist: your email address and the record of your consent, so the announcement can be sent when access opens. It operates in the United States under a data-processing agreement.
Google Analytics processes visit data if you agree to it. It records which pages were viewed, not anything you have typed into a calculator, and it holds nothing you have given Monverdo.
Two other companies are involved in running Monverdo without holding anything about you. Framer serves this website. Google Workspace runs the business’s own email and files.
That is the complete position today. The full register, with what each provider does, where it operates and when the list was last checked, is kept at subprocessors. It is maintained there rather than here so there is one list rather than two that drift apart.
What is deliberately not claimed
Monverdo is building a product that will hold real financial records. Substantial controls are designed for it. None of them protects you today, because the system they protect does not yet exist. Claiming them here would be dishonest.
Encryption of stored records
A requirement of the product under construction. There is no stored financial record today to encrypt.
Separation between accounts
The architecture is specified so that one account can never read another. It remains untested in production, because there are no accounts.
Two-factor sign-in
Planned for the release that introduces accounts. There is nothing to sign in to at present.
Backups with a tested restore
Written into the security policy with a deadline against it. It is not yet running. That gap is recorded internally as an accepted risk with an expiry date rather than left undocumented.
You will not find grand security adjectives anywhere on this site. Phrases of that kind are constructed to sound like a standard whilst committing to nothing. A financial product caught overstating its security has spent the only asset it genuinely owns.
How this is governed
Monverdo operates to a written security policy, adopted and signed, with a fixed review date and a quarterly audit against a documented checklist. Risks are maintained on a register. Where a commitment has not yet been met, it is logged as an exception with an expiry date rather than omitted from the list.
That is a statement about process rather than a promise of protection. It is included because how a company conducts itself before it has customers tends to predict how it conducts itself afterwards.
Monverdo is POPIA-aligned. Alignment rather than compliance, deliberately: the Information Officer registration is still in progress. This page will say “compliant” on the day that is confirmed, not before. The full detail is in the privacy policy.
If a security incident affects your data you will be notified directly and promptly, rather than left to work out from a general notice whether you were affected. Suspected issues may be reported to security@monverdo.com.