Trust & security

Security is part of how Marcenta is built

A plain-English overview of how Marcenta approaches customer data, access controls, infrastructure, AI safeguards, and security operations.

Last updated:

Security overview

The controls that shape our approach

Customer data remains yours

You retain ownership of the data you connect, upload, and generate in Marcenta.

Data is protected

Core controls include encryption in transit and at rest, tenant isolation, and access restrictions.

Access is scoped

Workspace access is role-based, while operational access is restricted to authorised personnel.

AI remains assistive

AI output can be inaccurate and should be reviewed by people before important decisions.

This overview is not a certification or a substitute for Marcenta's legal terms. No system can guarantee absolute security.

Designed for business performance context

Marcenta is designed for aggregated marketing analytics and business performance data from connected systems such as GA4, Search Console, advertising platforms, and CRM tools.

Depending on your configuration, connected sources may include some personal data. You control what data is connected and should avoid sending prohibited, sensitive, or unnecessary personal data.

Your organisation controls its connected data

  • You retain ownership of data you connect, upload, and generate in Marcenta.
  • Marcenta processes customer data to provide and secure the service on your organisation's behalf.
  • You control integrations and can disconnect sources based on available product controls.

Protection across storage, access, and operations

  • Encryption in transit and at rest.
  • Organisation-scoped tenant isolation and role-based access controls.
  • Access restricted to authorised personnel for legitimate service operations.
  • Operational and activity logging for key product and system events.
  • Monitoring for misuse, reliability, and security events.
  • Incident handling processes designed to investigate, contain, and remediate material incidents.

Customers are responsible for managing workspace permissions and protecting account credentials.

Minimise context and keep people in the decision loop

  • We use a data-minimisation approach before sending context to AI providers.
  • We do not intentionally send raw sensitive personal data to AI providers.
  • Our AI providers state that API-submitted content is not used for model training by default, subject to their terms and policies.
  • AI outputs may be inaccurate and should be reviewed by people before important decisions.
  • Marcenta is assistive software, not an automated decision-maker for your business.

Third-party providers support the service

Marcenta runs on third-party infrastructure and service providers. Current providers used for database, hosting, AI features, and email delivery are published on the Subprocessors page.

Talk directly with the Marcenta team

If your team has trust or security questions, email legal@marcenta.ai. Security-related disclosures may be handled confidentially where appropriate.

Have a security or privacy question?

Contact us directly for trust questions, security reviews, or responsible disclosures.

Contact security