MarkMate is an AI marketing operating system for teams that need useful automation without handing an agent an invisible write button. This page describes implemented control boundaries and our release posture. It is not a claim of certification, uninterrupted availability, or a substitute for your own vendor review.
1. Release truth
Public pages are generated from the same rollout-aware catalog that controls discovery and execution. A connector or workflow is not advertised as generally available merely because provider code exists. Provider acceptance, credentials, policy configuration, and production verification are separate gates. Current runtime readiness is shown on the status page.
- Disabled capabilities are hidden from public discovery and behave as unavailable.
- Beta or private-zone capabilities are labeled and scoped to approved workspaces.
- Release evidence records the actual agent identity, commands, results, and open risks.
2. Tenant boundaries
Workspace membership, role checks, database constraints, and tenant-scoped queries form the access boundary. A client portal is read-only and signed, expires automatically, can be revoked, and cannot approve, schedule, publish, or execute an operation. Agency portfolios group workspaces without granting cross-workspace access.
3. Approval boundary
Read operations may execute within the workspace policy. Operations that change a live external system are prepared first with the exact side effect, inputs, approval requirement, and idempotency context. A human workspace member must approve before execution, and the result is verified and recorded. AI agents and model-callable tools cannot approve writes.
4. Credentials and access
- Third-party connections use provider OAuth rather than asking users to paste tokens into an agent.
- Connection secrets are encrypted in the server-side vault and are workspace-scoped.
- OAuth scopes are requested according to the selected operation and provider policy.
- Owner/admin boundaries apply to connection management, policy changes, and approvals.
5. Data lifecycle
Workflows, reports, approvals, audit records, and uploaded artifacts remain tenant-scoped. Artifact deletion removes the application-visible record immediately; any external mirror cleanup is retried durably. Details about personal and connected-platform data are in the Privacy Policy, and account use is governed by the Terms of Service.
6. Availability and incidents
The status page reads the public readiness contract and reports the API, PostgreSQL, and Redis dependency state only when the signed-in service proves it. A failed or malformed readiness response is shown as unavailable or unknown rather than silently marked healthy. For an account or security incident, contact support@markmateos.com with the affected workspace and approximate UTC time; do not include credentials or access tokens.
7. Responsible disclosure
Please report suspected security issues privately to support@markmateos.com with “security report” in the subject. Include a concise description, reproduction steps, impact, and the minimum evidence needed to reproduce the issue. Do not access, modify, or retain another customer's data. We will acknowledge a report and coordinate a safe investigation; please do not publish an exploitable detail before we agree on disclosure timing.