Controlled intake
Online inquiry delivery remains closed unless origin validation, request limits, anti-abuse controls, Turnstile, and private server-side routing are configured together.
SECURITY
Monarch treats the public website as an operating surface, not a brochure isolated from engineering. Security language is tied to controls that can be verified in the deployed system.
Online inquiry delivery remains closed unless origin validation, request limits, anti-abuse controls, Turnstile, and private server-side routing are configured together.
The public site is designed to avoid collecting sensitive information that is unnecessary for a defined operating purpose.
Monarch may publish its approved studio mailbox, while routing credentials, provider secrets, and private service destinations remain server-side.
Inquiry endpoints and sensitive workflow responses are configured to bypass browser and CDN storage.
Security claims are published only when the corresponding control exists and is covered by the release verification contract.
RESPONSIBLE DISCLOSURE
Monarch does not publish a vulnerability mailbox unless the receiving workflow is actively monitored and owned. People with an established Catalyst contact should use that existing channel for urgent security matters and avoid including credentials, private keys, or unnecessary sensitive data.