MarkMate
Sign in
Back to MarkMateReadable legal. Real AI boundaries.

Trust Center

The controls behind MarkMate, the boundaries we keep explicit, and the evidence you should expect before a feature is called generally available.

Updated August 4, 2026Human veto documentedAI boundaries included
READConnected evidenceTHINKAI analysisWRITEHuman approval first
On this page
01Release truth02Tenant boundaries03Approval boundary04Credentials and access05Data lifecycle06Availability and incidents07Responsible disclosure
Legal documentsPrivacyTermsTrust CenterService status

MarkMate is an AI marketing operating system for teams that need useful automation without handing an agent an invisible write button. This page describes implemented control boundaries and our release posture. It is not a claim of certification, uninterrupted availability, or a substitute for your own vendor review.

1. Release truth

Public pages are generated from the same rollout-aware catalog that controls discovery and execution. A connector or workflow is not advertised as generally available merely because provider code exists. Provider acceptance, credentials, policy configuration, and production verification are separate gates. Current runtime readiness is shown on the status page.

  • Disabled capabilities are hidden from public discovery and behave as unavailable.
  • Beta or private-zone capabilities are labeled and scoped to approved workspaces.
  • Release evidence records the actual agent identity, commands, results, and open risks.

2. Tenant boundaries

Workspace membership, role checks, database constraints, and tenant-scoped queries form the access boundary. A client portal is read-only and signed, expires automatically, can be revoked, and cannot approve, schedule, publish, or execute an operation. Agency portfolios group workspaces without granting cross-workspace access.

3. Approval boundary

Read operations may execute within the workspace policy. Operations that change a live external system are prepared first with the exact side effect, inputs, approval requirement, and idempotency context. A human workspace member must approve before execution, and the result is verified and recorded. AI agents and model-callable tools cannot approve writes.

4. Credentials and access

  • Third-party connections use provider OAuth rather than asking users to paste tokens into an agent.
  • Connection secrets are encrypted in the server-side vault and are workspace-scoped.
  • OAuth scopes are requested according to the selected operation and provider policy.
  • Owner/admin boundaries apply to connection management, policy changes, and approvals.

5. Data lifecycle

Workflows, reports, approvals, audit records, and uploaded artifacts remain tenant-scoped. Artifact deletion removes the application-visible record immediately; any external mirror cleanup is retried durably. Details about personal and connected-platform data are in the Privacy Policy, and account use is governed by the Terms of Service.

6. Availability and incidents

The status page reads the public readiness contract and reports the API, PostgreSQL, and Redis dependency state only when the signed-in service proves it. A failed or malformed readiness response is shown as unavailable or unknown rather than silently marked healthy. For an account or security incident, contact support@markmateos.com with the affected workspace and approximate UTC time; do not include credentials or access tokens.

7. Responsible disclosure

Please report suspected security issues privately to support@markmateos.com with “security report” in the subject. Include a concise description, reproduction steps, impact, and the minimum evidence needed to reproduce the issue. Do not access, modify, or retain another customer's data. We will acknowledge a report and coordinate a safe investigation; please do not publish an exploitable detail before we agree on disclosure timing.

© 2026 MarkMatesupport@markmateos.com