Enterprise security. Honest transparency.
MarketingOS protects your data with encryption, strict tenant isolation, role-based access, and complete audit trails — and no AI agent ever acts without your consent.
Encryption at rest & in transit
All traffic uses TLS 1.2+. OAuth tokens are encrypted with AES-256-GCM. Connector credentials are secured with Fernet symmetric encryption at the application layer.
Strict multi-tenant isolation
Every database query is scoped by tenant ID — cross-tenant access is structurally impossible, not just discouraged. Enforced throughout the entire stack.
Secrets management
No secrets in code. Environment-based configuration; API keys, OAuth tokens, and connector credentials are encrypted before they touch storage.
Human approval gates
No AI agent can spend money, publish content, or take external action. Every recommendation requires explicit human approval with budget impact, risk assessment, and evidence.
Role-based access control
Six distinct roles (super_admin, agency_operator, client_admin, client_member, approver, readonly) with granular permissions. Operator and client portals are separated at middleware and API level.
AI transparency & provenance
Per-section confidence scores, data-source labeling, mock vs. live indicators, and full agent provenance — you always see what a recommendation is based on.
Complete audit trail
Every state change is logged with actor, action, target, and timestamp. Agent runs track model, tokens, duration, and confidence for every specialist.
Rate limiting & input validation
Authentication endpoints are rate-limited (20 requests / 60s per IP). All inputs are validated with Pydantic schemas — no arbitrary string injection.
Honest connector states
Connectors report their true state — live, mock, or not configured. The platform never pretends data exists when it doesn't.
From connection to decision — with you in the loop
You connect a platform
OAuth grants read-scoped access. Credentials are encrypted immediately (AES-256-GCM / Fernet) and stored tenant-scoped.
Agents analyze in isolation
Your data is read into an isolated analysis run for your workspace only. Insights carry data-source labels and confidence scores.
Actions wait for a human
Anything with budget or publishing impact goes to the approval queue. You (or your designated approver) decide. Everything is logged.
Transparent by design
MarketingOS is in early-access beta. We don't claim certifications we don't hold — we maintain public security documentation covering our current posture and hardening roadmap. Ask for the latest security review at support@marketingos.app. For evaluation, we recommend the sandbox: mock data, no live credentials, full functionality.
Questions about security?
Review our security documentation, or evaluate the platform with demo data — no live credentials needed.