Our approach
Security is foundational to Marivue, not an afterthought. Because we connect to a terminal’s most operationally sensitive systems, we design every part of the platform around least privilege, defense in depth, and data minimization. The guiding principle is simple: adding Marivue should never increase your risk.
Secure TOS integration
- Read-only by default. Marivue reads from your TOS through the channels it already exposes (database replicas, message queues, EDI/API feeds) and never writes back to your system of record.
- Least privilege. We connect with the minimum scopes required; credentials are scoped, rotated, and auditable.
- No surprise egress. With private-VPC or on-premise deployment, your operational data never has to leave your environment.
Encryption & data protection
- In transit: TLS 1.2+ for all connections, including the TOS integration link.
- At rest: AES-256 encryption for stored data, with optional customer-managed encryption keys.
- Tenant isolation: customer data is logically isolated per tenant, with data minimization applied throughout the pipeline.
Access control
- Role-based access control (RBAC) with least-privilege defaults.
- Single sign-on (SSO/SAML) and multi-factor authentication for administrative access.
- Internal access to customer environments is restricted, logged, and reviewed periodically.
Infrastructure & deployment
Marivue can be deployed to fit your security requirements:
- Marivue cloud — managed, hosted in a region you select.
- Private VPC — runs inside your own cloud account.
- On-premise — runs fully behind your firewall.
Environments use network segmentation, firewalls, and hardened baseline configurations. Production access is separated from development and limited to authorized personnel.
Application security
- Secure software development lifecycle with peer code review.
- Dependency scanning and software composition analysis.
- Static and dynamic testing as part of our release process.
- Secrets management and infrastructure-as-code review.
Monitoring & logging
We maintain centralized logging, metrics, and alerting across the platform. Security-relevant events are recorded to support detection, investigation, and audit, with access to logs restricted to authorized personnel.
Vulnerability management
We track and remediate vulnerabilities on a risk-prioritized basis, apply timely patching, and intend to conduct independent penetration testing as part of our path to general availability. Findings are triaged and resolved according to severity.
Incident response
We maintain a documented incident response process covering identification, containment, eradication, recovery, and post-incident review. In the event of a personal data breach affecting customer data, we notify affected customers without undue delay, consistent with our Data Processing Addendum.
Resilience & backups
Customer data is backed up, and we maintain business continuity and disaster recovery practices appropriate to the deployment model. Because Marivue is read-only and your TOS remains the system of record, your core operations are never dependent on Marivue’s availability.
Compliance program
- SOC 2 & ISO 27001 — program designed to align with these frameworks; formal certification in progress.
- GDPR — GDPR-ready data processing, supported by our DPA and Standard Contractual Clauses for international transfers.
- SSO/SAML & on-premise — available to meet enterprise and high-security requirements.
Current attestations, questionnaires, and our security roadmap are available to prospective customers under NDA.
Responsible disclosure
We welcome reports from security researchers. If you believe you’ve found a vulnerability, please email security@marivue.com with details and steps to reproduce. We commit to acknowledging reports, investigating promptly, and not pursuing good-faith research conducted under this policy.
Contact
For security questions, documentation requests, or to report an issue, contact security@marivue.com.