Separation between businesses
Each business's knowledge lives under its own key, and every read is filtered by that key inside the database rather than by the application asking politely. A request carrying one business's credential cannot address another's material, files, conversations or corrections — not by identifier, not by file path, not by a shared link.
We test this rather than assert it: an automated suite creates two businesses, has one store material and a file, and then attempts to reach both as the other by every route we can think of. Every attempt must fail, and the suite runs before any change reaches production. A failure stops the release.
Encryption
Data is encrypted in transit with TLS, and encrypted at rest by our infrastructure provider using AES-256. Files are held in private storage with no public read path; the only way to reach one is a short-lived link issued after we have checked that the file belongs to the business asking.
We do not offer customer-managed encryption keys, and we do not claim end-to-end encryption: we process message text in order to answer questions, so we can read it while doing so.
Where the data lives
In our database and file storage in the European Union (Ireland). Answering a question also sends the relevant passages and the customer's question to our model provider, which processes them in the United States.
We do not offer data residency in Nigeria, or anywhere else, today. If your regulator requires it, we cannot serve you yet, and we would rather tell you now than after a procurement process.
How long we keep it
Your material and corrections are kept until you remove them. Customer conversations are kept for as long as you choose — you can set 30 days, 90 days, six months, a year, or indefinitely, and older conversations are then removed automatically.
You can take a complete copy of everything in your workspace at any time, without asking us, and you can delete conversations or the whole workspace yourself. A deletion removes the rows and the stored files; we count what remains afterwards and show you that count, so the deletion is verified rather than promised.
Who can do what
Beyond an owner, a workspace can have an administrator (settings and team, but not billing) and a support member (the desk and the conversations, nothing else). Permissions are enforced in the database, so a member cannot reach an owner's screen by guessing an address.
We do not yet offer a figures-only role for an analyst, and company sign-in through SAML, OpenID Connect, Google Workspace or Microsoft Entra is not live: your settings can register the request, and we set it up by hand with you. No workspace is running on it today.
Evidence
Permission and role changes, exports, deletions, retention changes, plan changes and access requests are recorded with who did it, what they did, when, and the address they did it from. Records can be added but never edited or removed, and each is sealed against the one before it, so an altered or missing record is detectable. You can run that check yourself, and export the trail.
Individual answers and refusals are not yet in that trail. They are held with the conversation, where you can read them on the desk, but they are not sealed into the chain.
Reliability, measured
Over the last 30 days we answered 710 questions. Our answering provider failed on 886 of them. Our standby provider took over and produced the answer 884 times; 2 customers were told, honestly, that we could not answer right then.
We run two model providers from two different companies. The second is used only when the first refuses the request or goes silent, never to save money and never in the middle of an answer. When it does answer a customer, the answer says so out loud — the standby is a little less capable, and we would rather tell someone that than quietly give them a thinner answer. Every claim in it is still taken from your own written knowledge.
If both providers are unavailable, we do not guess. The customer is told we cannot answer right now and the conversation is handed to a person.
We do not publish an SLA. We have not been running long enough to commit to a number we could be held to, and a figure invented for a sales page is worth nothing. We will publish one when we have twelve months of this measurement behind us.
Who we rely on
Supabase (database, files, authentication — EU), Cloudflare (serving the application), OpenAI (answering questions), Resend (email), and Meta's WhatsApp Business platform (the first message to a business owner, where they have turned it on). Nothing else sees customer messages.
What we do not hold
We are not SOC 2 audited. We are not ISO 27001 certified. We hold no PCI attestation, and we are not a HIPAA business associate. We have not commissioned an independent penetration test.
These are on our roadmap in that order, and we will date them on this page when they are real. If your procurement requires any of them today, we are not the right choice yet — and if you tell us which one blocks you, that genuinely moves it up the list.
Reporting something
If you believe you have found a way for one business to reach another's data, write to security@mara.support. We will confirm within one working day, and we would rather hear about it from you than from a customer.
Or read how it works.