Trust boundary
AI-NATIVE GOVERNANCE

The living system of record for security governance

Every claim starts as a declaration, is backed by evidence, and rises in confidence as it is verified. Your organization's security posture becomes a living, verifiable layer of knowledge — ready for every new assessment.

Claims are updating live
Product

This is how a claim lives

One sentence. Who stated it, what backs it, when it was verified. All in the same record.

1A claim is a sentence: a proposition that can be true or false, tested by events.
2Verification level rises step by step: it starts as a declaration, is backed by evidence, then monitored through integration.
3Freshness decays over time. If a record is not kept current, its status drops automatically.
Claims / CLM-0047

Identity & Access Management › Strong Authentication

All externally-exposed enterprise and third-party applications enforce MFA.

CLM-0047·Scope: All externally-exposed applications and their user accounts

Status: Satisfied· reviewedFreshness: 30 daysOwner: Elif Aydın
Verification level
Self-declaration
The organization's own declaration
✓ 23 Aug 2026
Reviewed evidence
Someone other than the attester reviews and approves the evidence
✓ 28 Aug 2026 · Elif Aydın
System observation
Status is read from the system itself via integration
later
Ledger3 records · Latest: review, 28 Aug 2026
Requirements it feeds4 mappings
CIS 6.3ISO A.5.15BİGR 3.2.1.10BİGR 4.1.3.5
Decisions / Pending · 3
CONTRADICTIONVerikent · supplier
Claim · declaredSatisfied· declared

Critical security updates are applied within 30 days.

Supplier declaration · 30 May 2026

CONTRADICTION
Observation · external surface scan29 Jul 2026

On two internet-facing servers: a known vulnerability whose patch has been available for 96 days, and a legacy TLS version still enabled.

System observation · population: 24 external assets

time-bound risk acceptanceReturns: 7 Sept 2026

Decision owner: Information Security Manager · rationale recorded

Product

When declaration and observation disagree

The supplier declares what it has in place. The system records how it looks from the outside. When the two disagree, the gap becomes visible and calls for a decision.

1Traditional approaches do not focus on catching situations like this.
2The declaration may well have been given correctly, but the reality on the ground may have changed over time.
3A contradiction is not eliminated, it is managed. If the risk is accepted, its term and its owner are set explicitly.
4Exceptions do not stay open indefinitely. When the term expires the matter is reopened for assessment; the old decision does not quietly carry on.

317 claims, 14 domains. Mapped to widely accepted frameworks.

CIS Controls v8.1ISO/IEC 27001:2022BİGR
The ledger

Status cannot be set by hand

At the core of Monmer is a ledger model that keeps the state of every claim current through events and evidence. A record holds for as long as the evidence behind it is current; when that evidence expires, the record is either renewed or its status changes on its own.

Add evidence or open an exception

There is no third option. No button marks a status compliant by hand. Because that button is what stops a record from being a record.

Exceptions do not extend quietly

Every exception and every risk acceptance carries a term. When it expires the decision returns to the table, and nobody has to remember it.

Every ratio says what it measures

64%, but 64% of what? Every measurement is shown together with its scope.

Product

The whole period on one timeline

Every change takes its place on the timeline. So at the end of a period you see not only the current state, but how the portfolio changed over the course of it.

Overview / Nova Holding
Group ledger
115 claims · 5 subsidiaries · 12 suppliers
Last event: 2 days ago
Satisfied· verified72Satisfied· declared19Satisfied· stale11Has gaps4Not satisfied3No attestation6
Timeline · 2026 · Q3replay
3 July

A new assessment was started.

23 July

A claim rose from declaration to system observation.

9 August

Contradiction detected, time-bound risk acceptance opened.

26 August

Exception expired, the decision returned to the table.

About us

We come from the field

For years we ran security governance inside organizations. We built Monmer not from theory, but from the needs we met in the field.

OS

Oğuz Sezgin

Co-founder

Former CIO at a large enterprise group, leading technology & security strategy across companies of all sizes. Believes strong security should be structured, practical and scalable without unnecessary complexity.

AS

Ali Can Sezer

Co-founder

Cybersecurity strategist with 10+ years building security programs and tooling for teams of all sizes. He has helped many companies in various industries operate and grow in a secure and compliant manner.

Our limits

What we do not promise

We treat an inflated promise as an unverified claim too. So we set out our limits.

We do not produce a health score.
A security score reduced to a single number hides the denominator behind it. We show the distribution of statuses; we do not grade.
Not everything is verified automatically.
For claims that rest on process documents such as policies, contracts and exercises, the highest level is reviewed evidence. This is not a shortfall; it is full verification for that kind of claim.
We do not eliminate the audit.
Periodic audit is a requirement of regulation, of contracts and of the board cycle. Continuous verification makes it practical and more honest; it does not replace it.
We do not leave the decision to AI.
A response is prepared and the record is written. But when a case requiring human review is detected, the flow stops and waits for approval.

Take your security governance to the next level

We are early, and we work deeply with a selected set of organizations. We start with your own requirement catalog.