Documentation contents
DOCS / SECURITY AND DATA HANDLING
Security and data handling
Public-facing security and privacy overview.
This page is a public overview. It describes control categories without exposing operational details that would weaken them.
Access control
Internal workspaces require authentication. User-owned analyses, runs, saved evidence profiles, financial profiles, simulations, and related child records are scoped to their owner. Administrative access is separate and should be used only for authorised support or governance purposes.
Session and request protection
The application uses server-managed sessions, request-forgery protection on state-changing actions, rate limits on sensitive routes, and security headers. Accounts are provisioned through the current controlled access process; public self-registration is disabled in the source baseline documented here.
Credentials
Third-party service credentials are stored separately from ordinary analysis content and protected at rest. Secrets should be supplied through the deployment environment or the credential-management interface, never embedded in uploaded datasets, briefs, source files, or screenshots.
Data minimisation
Collect only material needed for the defined analysis. Public review and social content should be minimised before external model processing, and direct identifiers should not be retained when they are not analytically necessary.
Retention and deletion
Users can remove eligible runs and account data through supported controls. Retention requirements may differ for active client work, contractual records, backups, security logs, and legally required records. The applicable engagement terms and privacy notice govern the final schedule.
Deployment
Marres supports containerised deployment with a PostgreSQL database and may use separate compute workers for intensive analysis. Production deployments should use managed secrets, encrypted transport, restricted network access, backups, monitoring, and an environment-specific incident process.
Reporting a concern
If you believe you have found a security issue, contact us at marres@marresinsights.com. Please include enough detail to reproduce the concern, and allow time for investigation before sharing it publicly.
Scope statement
This overview is not a certification and should not claim compliance with a standard that has not been independently assessed. Detailed architecture, audit procedures, sub-processor configuration, and incident playbooks belong in controlled assurance materials.
Related product page: Security overview
Documentation draft · Source baseline 16 August 2026
