Ask and Insights are not AI
Every answer is computed from your catalog and cites its basis. We do not use a language model, we do not train on workspace content, and Ask is not a chatbot. See the FAQ.
Encryption and isolation
- TLS in transit. Integration tokens and webhook secrets are encrypted at rest (AES-256-GCM).
- Every workspace route checks membership. A non-member gets 404, not a hint that the workspace exists.
- Roles (owner, admin, manager, stakeholder) and product-level access restrict what members see.
- Staff console access is logged. Sentry scrubs credentials and request bodies.
Retention and deletion
Owners can delete a workspace from Settings. Workspace content is removed from live systems within 30 days of deletion, and from backups within 90 days (volume snapshot policy — ops, not an application job). Account data is deleted or anonymised within 30 days. Billing records are kept for six years. See the privacy policy.
Payments (PCI)
We never store card numbers. Checkout and cards are processed by Lemon Squeezy, our merchant of record. We keep card brand and last four digits only. We do not claim that Marqab is PCI DSS certified.
SOC 2
We run a security program that maps to the Trust Services Criteria we already implement (encryption, TLS, RBAC, staff audit, Sentry scrub). We are not SOC 2 certified. A Type I report needs an observation period and evidence we do not yet publish.
Health data
Marqab is not intended to store protected health information. We do not sign BAAs and we do not claim HIPAA compliance.
GDPR
Subject-rights requests go to [email protected]. A data processing agreement is available to download. Sub-processors are listed separately.
Report a vulnerability
Email [email protected]. Please do not file a public issue with exploit details. We will acknowledge receipt and keep you updated.