Security and privacy are our top priority, and every layer of how we build, host and run the platform is designed to keep that access in your hands, and only your hands.
For full technical details, see the Marblism Trust Center.
The short version
CASA Tier 2 certified, audited by TAC Security (an App Defense Alliance lab).
AES-256 encryption at rest and TLS 1.2+ in transit.
24/7 monitoring with anomaly detection and on-call response.
Your data never trains an AI model — ours or anyone else’s.
Independently audited
We don’t grade ourselves on security. Independent third parties do.
Framework | Status | Issuer |
CASA Tier 2 | Verified | TAC Security |
GDPR (EU 2016/679) | Aligned | — |
CCPA / CPRA | Aligned | — |
Google API User Data Policy | Compliant | Google Limited Use |
PCI DSS | Compliant | Outsourced via Stripe (Level 1) |
How your data is protected
Your data is encrypted, end to end. TLS 1.2+ in transit, AES-256 at rest. Encryption keys live in cloud-native KMS, are rotated on a documented schedule, and are never exposed to staff.
Your data lives on hardened infrastructure. Customer data is processed and stored on Amazon Web Services in regions covered by SOC 2 Type II and ISO 27001 attestations. Every endpoint sits behind a WAF, rate limiting and DDoS mitigation.
Your workspace is fully isolated. We isolate customer data at the application, database, queue and object-storage layers. Your AI Employees can only see your workspace — never another customer’s data
.
Your credentials are safe. OAuth tokens are encrypted with industry-standard cryptography and stored separately from customer content. Marblism staff use SSO with mandatory MFA, and production access is gated through short-lived credentials with full audit logging.
Your activity is monitored 24/7. Centralized logging, anomaly detection and an on-call rotation watch the platform around the clock. Suspicious activity automatically triggers rate limits and human review.
Your platform is tested by humans, not just code. Annual third-party penetration test, quarterly internal reviews, and automated SAST, DAST and dependency scanning on every commit before code reaches production.
Where is my data stored?
Customer data is stored in Amazon Web Services (us-east-1).
What happens to my data if I cancel?
Your workspace is deactivated immediately and customer content is deleted within 30 days, except where retention is required by law. A full export is available on demand before cancellation.
Learn more
For the full list of certifications, security controls, subprocessors, and frequently asked questions, visit the Marblism Trust Center.
