Your marketing data, isolated and controlled
This page is maintained by MarklyticsAI to answer common security and privacy questions about the platform. It describes the controls we operate today; it is not a certification or an independent audit.
Multi-tenant isolation
Every workspace owns its data. Records carry a tenant key enforced at the database layer.
Row level security
Business tables use row level security policies so a query can only return your workspace's rows.
Role based access
Owner, admin, marketing manager, sales manager and executive roles each see a scoped dashboard.
Managed authentication
Sign-in, invitations and session handling are managed by our cloud auth provider.
Encryption in transit
All traffic between your browser and the platform is served over HTTPS.
Private file storage
Uploaded import files are stored in a private bucket under a tenant-scoped path.
Activity trails
Import logs and enquiry timelines are append-only, so history cannot be silently rewritten.
Least privilege by default
Delete rights are restricted to owners and admins; shared templates stay read-only.
Shared responsibility
MarklyticsAI is responsible for the platform: hosting, application code, tenant isolation logic, access control enforcement and keeping the service available.
Your team is responsible for who you invite, the roles you assign, the accuracy of the data you upload, and following your own organisation's policies for the customer data you bring into the platform.
Your customers interact with your brand through Meta and WhatsApp. Consent and communication preferences for those conversations remain governed by your own privacy notice and the policies of those channels.
We do not currently claim SOC 2, ISO 27001, HIPAA or PCI compliance. If your procurement process requires formal documentation, contact us and we will share what we can.
Report a vulnerability
Found something that looks wrong? Email security@marklyticsai.com with steps to reproduce. We acknowledge reports and will keep you updated on the fix.