Security

Boring on purpose.

Margo holds the keys to your ad accounts, your email list, and your revenue data. That deserves plain answers, not a wall of badges. Here is exactly what we do today.

What's in place today
+
Encryption in transit

TLS on every connection — browser to Margo, Margo to every platform it operates.

+
Encryption at rest

All data lives in managed Postgres with encryption at rest. No self-rolled storage.

+
OAuth tokens encrypted

The credentials that let Margo operate your channels are encrypted at rest, separately from application data.

+
Role-based access

Admin, manager, and viewer roles scope what each person in your workspace can see and approve.

+
Full audit log

Every autonomous action Margo takes is logged — what, when, under which authority. The log is the contract.

+
Per-channel kill switch

Any channel can be halted instantly, independently of the others. Autonomy is always revocable.

+
Rate limiting

API surfaces are rate-limited to blunt abuse and credential-stuffing attempts.

+
Security headers + CSP

Strict security headers and a content security policy on the application, as a baseline rather than a bragging right.

+
Data deletion on request

EU-owned infrastructure. Your data is exportable while you’re a customer and deleted on request when you leave.

What we don't claim

SOC 2 is on the roadmap — it is not something we hold today, and we won't put the badge on this page until an auditor says we've earned it. If your procurement process needs specifics in the meantime, ask us directly and we'll walk you through our controls as they actually stand.

Found something?

If you believe you've found a security issue in Margo, we want to hear about it before anyone else does. Write to sales@citepulse.io and we'll respond quickly and take it seriously.