Security
What we can actually back up
We would rather list the specific things that are true than assert a compliance label. If you need something checked in more detail, ask — see contact below.
Where your data lives
Application data is hosted on servers we operate ourselves in the United Kingdom, not spread across a third-party shared cloud platform.
Encryption in transit
Every connection to the marketing site, the application and the API is HTTPS only.
Encryption at rest
Sensitive fields — client credentials, connected-account tokens (Shopify, Xero, QuickBooks) and email connection credentials — are encrypted in the database, not stored as plain text.
Backups
Database backups are taken automatically and kept so a restore is possible if something goes wrong. A backup is also taken immediately before every deployment.
Access control
Two-factor authentication is available on every account, roles and per-person permissions control what a team member can see, and an IP allowlist can restrict sign-in to your own team's addresses.
The customer API
Off by default. When switched on, keys are scoped per resource and per verb, owned by the agency rather than by the person who created them, and revocable individually.
Sub-processors
Who else touches your data, and why
Stripe
Payment processing for subscriptions and, where you use it, your own client invoicing.
Mailgun
Transactional email — invoices, notifications, ticket replies.
Bunny
Content delivery for this marketing website and static assets.
Data Processing Agreement
If your agency needs a signed DPA for your own compliance work, email hello@marquecrm.com and we'll send one over.
Found a problem?
If you find a security issue, tell us at hello@marquecrm.com before disclosing it anywhere else, and we'll deal with it as a priority.