Trust & reliability
monoclose reads from the Xero or Sage you already run, locks every closed period against silent edits, and records full provenance on every agent action — real architecture, not a marketing claim.
Underway
SOC 2 & ISO CERTIFICATION
We're pursuing formal certification — not claiming it before we've earned it.
Locked
CLOSED PERIODS
A signed-off number never quietly changes underneath you.
Full
PROVENANCE TRAIL
Every agent action records what it looked at and why.
Xero · Sage
YOUR OWN CONNECTORS
monoclose never becomes a second system of record.
One review path
Every reconciliation and journal is grounded in your real data and carries its own evidence trail. Anything that crosses a materiality threshold — or falls below a confidence threshold — gets surfaced for a person to resolve, not silently pushed through.
01
monoclose reads from the Xero or Sage you already run over the same connectors you'd use anywhere else. Where a connection needs file storage instead of an ERP feed, it requests the narrowest scope that works — Google Drive's connector uses drive.file, not access to your whole account.
02
Agents reconcile accounts and post journals with the source, balance, and reasoning behind each line recorded as they go — the working paper shows the logic, not just the final number.
03
Small, high-confidence items complete on their own. Anything that crosses a materiality threshold, or anything the agent isn't confident about, is surfaced for a person to resolve — the agent flags, a person decides, every time.
Security baseline
A closed period rejects silent edits outright — a signed-off number never quietly changes underneath you.
Every agent action records what it looked at and why, on every line — not just a final balance.
monoclose reads from the Xero or Sage you already run. It doesn't become a second system of record.
Connections request only the scope the job needs — a file-storage connector asks for the files it manages, never your whole account.
Connector tokens are versioned and rotated, not left as a single static key indefinitely.
A small item handled with total certainty and a large one handled with real doubt are never treated as the same problem.
Certification roadmap
None of these are held yet — we're building the underlying controls first, then pursuing formal certification, rather than the other way around. This is specifically what "underway" means.
An independent audit of the controls that actually run monoclose day to day — not a one-time checklist, an ongoing one.
A recognized standard for how we manage information security as a whole system, not just individual controls.
South Africa's own data protection law — the one that actually governs the client data running through monoclose, not a borrowed overseas equivalent.
The newer standard for how AI systems specifically are governed — relevant to monoclose in a way most close software doesn't have to think about yet.
We're happy to walk your security or compliance team through the architecture directly — locked periods, provenance, connector scopes, all of it.