Trust

Security at Marskel

Your company data is sensitive. Here is how we protect it and what to do if you discover a problem.

🔐

Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Supabase manages encryption keys with hardware security modules.
🏗️

Infrastructure

Marskel runs on Supabase (Postgres) with row-level security enforced at the database layer. Your data is isolated from other customers by tenant ID at every query.
🔑

Authentication

Accounts use Supabase Auth with Google OAuth and email magic links. Passwords are never stored. Sessions use short-lived JWTs with refresh rotation.
🛡️

Access control

Marskel employees have access only to anonymized usage metrics. No employee can read your workspace content without your explicit support request and temporary access grant.
💳

Payments

Payment details are handled entirely by Stripe. Marskel never touches your card number, CVC, or bank credentials.
📋

Expert confidentiality

Experts who review deliverables sign NDAs before onboarding. They see only the specific deliverable submitted for review, not your full account or conversation history.

Sub-processors

We use a small number of third-party processors, each with their own security programs:

SupabaseDatabase, auth, and storage
Security page
AnthropicAI inference (Claude API)
Security page
StripePayment processing (PCI DSS Level 1)
Security page
ResendTransactional email
Security page
VercelApplication hosting and CDN
Security page

Responsible disclosure

If you discover a security vulnerability in Marskel, please report it to us before disclosing publicly. We commit to:

  • Acknowledge your report within 2 business days
  • Keep you informed as we investigate and remediate
  • Credit you publicly (if desired) once the issue is resolved
Report a vulnerabilitysecurity@marskel.com
Privacy PolicyTerms of Service