What we can actually back up

We would rather list the specific things that are true than assert a compliance label. If you need something checked in more detail, ask — see contact below.

Where your data lives

Application data is hosted on servers we operate ourselves in the United Kingdom, not spread across a third-party shared cloud platform.

Encryption in transit

Every connection to the marketing site, the application and the API is HTTPS only.

Encryption at rest

Sensitive fields — client credentials, connected-account tokens (Shopify, Xero, QuickBooks) and email connection credentials — are encrypted in the database, not stored as plain text.

Backups

Database backups are taken automatically and kept so a restore is possible if something goes wrong. A backup is also taken immediately before every deployment.

Access control

Two-factor authentication is available on every account, roles and per-person permissions control what a team member can see, and an IP allowlist can restrict sign-in to your own team's addresses.

The customer API

Off by default. When switched on, keys are scoped per resource and per verb, owned by the agency rather than by the person who created them, and revocable individually.

Who else touches your data, and why

Stripe

Payment processing for subscriptions and, where you use it, your own client invoicing.

Mailgun

Transactional email — invoices, notifications, ticket replies.

Bunny

Content delivery for this marketing website and static assets.

Data Processing Agreement

If your agency needs a signed DPA for your own compliance work, email hello@marquecrm.com and we'll send one over.

Found a problem?

If you find a security issue, tell us at hello@marquecrm.com before disclosing it anywhere else, and we'll deal with it as a priority.