Boring on purpose.
Margo holds the keys to your ad accounts, your email list, and your revenue data. That deserves plain answers, not a wall of badges. Here is exactly what we do today.
TLS on every connection — browser to Margo, Margo to every platform it operates.
All data lives in managed Postgres with encryption at rest. No self-rolled storage.
The credentials that let Margo operate your channels are encrypted at rest, separately from application data.
Admin, manager, and viewer roles scope what each person in your workspace can see and approve.
Every autonomous action Margo takes is logged — what, when, under which authority. The log is the contract.
Any channel can be halted instantly, independently of the others. Autonomy is always revocable.
API surfaces are rate-limited to blunt abuse and credential-stuffing attempts.
Strict security headers and a content security policy on the application, as a baseline rather than a bragging right.
EU-owned infrastructure. Your data is exportable while you’re a customer and deleted on request when you leave.
SOC 2 is on the roadmap — it is not something we hold today, and we won't put the badge on this page until an auditor says we've earned it. If your procurement process needs specifics in the meantime, ask us directly and we'll walk you through our controls as they actually stand.
If you believe you've found a security issue in Margo, we want to hear about it before anyone else does. Write to sales@citepulse.io and we'll respond quickly and take it seriously.