Short answer
Marek AI security and data approach
Marek is designed to use only company-selected tool connections and credentials, with role-based invocation, revocable access, per-tool permissions, approval gates, spending limits, and an audit trail. Marek is pre-launch and does not currently claim security certifications.
A connection is not a blank cheque
The intended design separates access to a tool from permission to perform every action in that tool. Administrators choose who may invoke Marek and whether an action is Always permitted, must Ask, or is Never allowed.
- Company-controlled credentials and connections
- Role-based invocation
- Per-tool and per-action boundaries
- Revocation and kill-switch controls
- Action records for review
Human decisions for higher-risk work
Public, irreversible, sensitive, or over-budget actions should be able to pause for a person. Governance lowers unnecessary authority; it does not remove the need for review and security operations.
What we do not claim
Marek is not generally available, has no public customers, and does not claim completed compliance certifications. Quebec Law 25 support and data-residency capabilities are product goals under development, not certified statements.
Questions
What teams ask before joining
- Is Marek security certified?
- No certification is claimed today. Marek is pre-launch and its production security controls are still being validated.
- Does Marek train on customer data?
- No definitive public production policy is claimed on this page yet. The final data-handling terms will be published before general availability.