Skip to content
    Marres Insights
    Documentation contents

    DOCS / SECURITY AND DATA HANDLING

    Security and data handling

    Public-facing security and privacy overview.

    This page is a public overview. It describes control categories without exposing operational details that would weaken them.

    Access control

    Internal workspaces require authentication. User-owned analyses, runs, saved evidence profiles, financial profiles, simulations, and related child records are scoped to their owner. Administrative access is separate and should be used only for authorised support or governance purposes.

    Session and request protection

    The application uses server-managed sessions, request-forgery protection on state-changing actions, rate limits on sensitive routes, and security headers. Accounts are provisioned through the current controlled access process; public self-registration is disabled in the source baseline documented here.

    Credentials

    Third-party service credentials are stored separately from ordinary analysis content and protected at rest. Secrets should be supplied through the deployment environment or the credential-management interface, never embedded in uploaded datasets, briefs, source files, or screenshots.

    Data minimisation

    Collect only material needed for the defined analysis. Public review and social content should be minimised before external model processing, and direct identifiers should not be retained when they are not analytically necessary.

    Retention and deletion

    Users can remove eligible runs and account data through supported controls. Retention requirements may differ for active client work, contractual records, backups, security logs, and legally required records. The applicable engagement terms and privacy notice govern the final schedule.

    Deployment

    Marres supports containerised deployment with a PostgreSQL database and may use separate compute workers for intensive analysis. Production deployments should use managed secrets, encrypted transport, restricted network access, backups, monitoring, and an environment-specific incident process.

    Reporting a concern

    If you believe you have found a security issue, contact us at marres@marresinsights.com. Please include enough detail to reproduce the concern, and allow time for investigation before sharing it publicly.

    Scope statement

    This overview is not a certification and should not claim compliance with a standard that has not been independently assessed. Detailed architecture, audit procedures, sub-processor configuration, and incident playbooks belong in controlled assurance materials.

    Related product page: Security overview

    Documentation draft · Source baseline 16 August 2026