Security

Boring on purpose.

Margo holds the keys to your ad accounts, your email list, and your revenue data. That deserves plain answers, not a wall of badges. Here is exactly what we do today.

What's in place today
+
Encryption in transit

TLS on every connection — browser to Margo, Margo to every platform it operates.

+
Encryption at rest

All data lives in managed Postgres with encryption at rest. No self-rolled storage.

+
OAuth tokens encrypted

The credentials that let Margo operate your channels are encrypted at rest, separately from application data.

+
Role-based access

Admin, manager, and viewer roles scope what each person in your workspace can see and approve.

+
Execution audit trail

Execution decisions and delivery outcomes are recorded in your workspace audit trail. Export the log to review activity with your team.

+
Workspace pause

Admins can pause new workspace execution for 24 hours and disable scheduling. A pause cannot recall a request already accepted by an external provider.

+
Rate limiting

Sign-in, account creation, invitations, and execution actions have shared production rate limits to reduce abuse.

+
Security headers + CSP

Strict security headers and a content security policy on the application, as a baseline rather than a bragging right.

+
Data deletion on request

Contact us to arrange data deletion. Audit logs can be exported within the app; other data requests are handled with the pilot support team.

What we don't claim

SOC 2 is on the roadmap — it is not something we hold today, and we won't put the badge on this page until an auditor says we've earned it. If your procurement process needs specifics in the meantime, ask us directly and we'll walk you through our controls as they actually stand.

Found something?

If you believe you've found a security issue in Margo, we want to hear about it before anyone else does. Write to sales@citepulse.io and we'll respond quickly and take it seriously.