monoclose

Trust & reliability

Enterprise-grade security, built for agentic close.

monoclose reads from the Xero or Sage you already run, locks every closed period against silent edits, and records full provenance on every agent action — real architecture, not a marketing claim.

Underway

SOC 2 & ISO CERTIFICATION

We're pursuing formal certification — not claiming it before we've earned it.

Locked

CLOSED PERIODS

A signed-off number never quietly changes underneath you.

Full

PROVENANCE TRAIL

Every agent action records what it looked at and why.

Xero · Sage

YOUR OWN CONNECTORS

monoclose never becomes a second system of record.

One review path

Agents work. Humans decide what matters.

Every reconciliation and journal is grounded in your real data and carries its own evidence trail. Anything that crosses a materiality threshold — or falls below a confidence threshold — gets surfaced for a person to resolve, not silently pushed through.

01

Your systems stay yours

monoclose reads from the Xero or Sage you already run over the same connectors you'd use anywhere else. Where a connection needs file storage instead of an ERP feed, it requests the narrowest scope that works — Google Drive's connector uses drive.file, not access to your whole account.

02

Every action keeps its evidence

Agents reconcile accounts and post journals with the source, balance, and reasoning behind each line recorded as they go — the working paper shows the logic, not just the final number.

03

Materiality decides what needs a person

Small, high-confidence items complete on their own. Anything that crosses a materiality threshold, or anything the agent isn't confident about, is surfaced for a person to resolve — the agent flags, a person decides, every time.

Security baseline

A clear baseline, today — not a promise for later.

Locked periods

A closed period rejects silent edits outright — a signed-off number never quietly changes underneath you.

Full provenance

Every agent action records what it looked at and why, on every line — not just a final balance.

Your data, your connectors

monoclose reads from the Xero or Sage you already run. It doesn't become a second system of record.

Least-privilege access

Connections request only the scope the job needs — a file-storage connector asks for the files it manages, never your whole account.

Rotated connector credentials

Connector tokens are versioned and rotated, not left as a single static key indefinitely.

Materiality-gated review

A small item handled with total certainty and a large one handled with real doubt are never treated as the same problem.

Certification roadmap

The compliance bar we're building toward.

None of these are held yet — we're building the underlying controls first, then pursuing formal certification, rather than the other way around. This is specifically what "underway" means.

SOC 2 Type II

Planned

An independent audit of the controls that actually run monoclose day to day — not a one-time checklist, an ongoing one.

ISO/IEC 27001

Planned

A recognized standard for how we manage information security as a whole system, not just individual controls.

POPIA compliance

Planned

South Africa's own data protection law — the one that actually governs the client data running through monoclose, not a borrowed overseas equivalent.

ISO/IEC 42001

Planned

The newer standard for how AI systems specifically are governed — relevant to monoclose in a way most close software doesn't have to think about yet.

Have a security question before you commit?

We're happy to walk your security or compliance team through the architecture directly — locked periods, provenance, connector scopes, all of it.