Security & Trust

Last updated: 7/28/2026.

Marcora (MarketCore LLC) gives go-to-market teams governed, on-brand context infrastructure for AI content. This page documents how we protect your data, exactly what is and isn't independently certified today, and what's on our roadmap: the answers a security review needs, stated plainly. Anything not covered here: security@marcora.ai.

Infrastructure and inherited compliance

Marcora runs on a small, deliberately chosen stack of independently audited providers.

ProviderRoleTheir certificationsWhat Marcora inherits
NetlifyWeb application hosting / CDNSOC 2 Type 2, ISO 27001, ISO 27018Edge security, build pipeline, DDoS protection
AnthropicAI content generation (API)SOC 2 Type 2, ISO 27001:2022, ISO 42001No training on your data; limited API retention
OpenRouter Routes all OpenAI-model requests: content generation, Context Intelligence, embeddings, extracted document text, and lifecycle email Not independently assessed by us
StripePaymentsPCI DSS Level 1, SOC 2We never store card data
Railway Application backend, database, file delivery, document conversion, and integration services (US) SOC 2 Type 2, SOC 3 Physical, network, and infrastructure controls; encryption at rest; audited platform operations
Mailgun (Sinch)Transactional emailSOC 2 Type 1 & 2, ISO 27001Audited email delivery
ComposioThird-party integrations layerSOC 2 Type 2, ISO 27001:2022Audited integration handling
PostHogProduct analyticsSOC 2 Type 2Audited analytics processing
OneSignalOpt-in notification emailsSOC 2 Type 2, ISO 27001, ISO 27701Audited notification delivery

What's independently certified, and what isn't: the certifications above are held by our infrastructure providers, and Marcora inherits the physical, network, and infrastructure controls they cover. Marcora (MarketCore LLC) has not yet completed its own independent SOC 2 or ISO 27001 audit. Our compliance roadmap is below, and enterprise customers can request our security documentation package at security@marcora.ai.

Additional subprocessors

These providers also process data on our behalf. They are listed separately from the table above because we disclose here what each one receives rather than certifications we have independently assessed.

  • OpenRouter — all OpenAI-model traffic: content generation, Context Intelligence, embeddings, text extracted from your uploads, and lifecycle email.
  • RapidAPI — receives the raw bytes of PDFs you upload, for text extraction.
  • Affonso — receives every user's name and email address at signup, not only those arriving through a referral.
  • Perplexity, Exa and Brave — receive the research and search queries you run.
  • Browserless and URLtoText — receive URLs you ask Marcora to fetch. They do not retain the retrieved content.
  • Google Cloud Storage — holds database backups and stored file objects.
  • Braintrust and Langfuse — receive a 0.01% sample of request traces as anonymised usage metadata. Privacy mode is enabled for both, so prompts and completions are stripped before the trace is sent.

Encryption

  • In transit: TLS 1.2+ on all connections.
  • At rest: provided by our infrastructure providers, plus application-level AES-256-GCM encryption (per-file random IVs, authenticated encryption, dedicated key management) for files in our file-delivery service.

Your data and AI

  • You own your content. We process it only to provide the Service.
  • Your content is not used to train AI models. We call Anthropic directly under its commercial API terms, and all OpenAI-model requests are routed through OpenRouter, whose data-collection settings on our account are configured so that neither paid nor free endpoints train on request data and prompts are never published.
  • Data residency: Marcora is hosted in the United States. Our application backend and database run on Railway's own US infrastructure; Google Cloud Storage holds database backups and stored file objects.

Access controls

  • Workspace role-based access control: admin, creator, and collaborator roles.
  • Least-privilege access to production systems; multi-factor authentication on all administrative and infrastructure accounts.
  • Programmatic access (API and MCP server) is authorized via OAuth 2.0 or workspace-scoped API keys that customers manage and can revoke at any time.
  • Signed, expiring URLs (15-minute validity) for file downloads.

Data retention and deletion

  • Cancelling a subscription downgrades you to our free tier; your data stays yours and stays put.
  • Account deletion (in-app or via support@marcora.ai) is completed within 30 days, except where law requires retention.
  • Your data is exportable at any time; you are never locked in.

Business continuity

  • Automated backups via our infrastructure providers; data exportable at any time in standard formats.
  • For enterprise agreements we offer continuity assurances on request, including data-export guarantees and escrow arrangements.

Responsible disclosure

Found a vulnerability? Email security@marcora.ai. We acknowledge reports within 2 business days.

Compliance roadmap

  • Today: independently audited (SOC 2 Type 2 / ISO 27001) infrastructure across every provider in our stack; application-level file encryption; DPA available on request; this page.
  • Next: documented internal security policies (access, incident response, retention); subprocessor-change notifications.
  • Planned: independent application-layer penetration testing; SSO and MFA for customer accounts; SOC 2 certification for MarketCore LLC.

Enterprise prospects: request our security documentation package at security@marcora.ai. It includes our security overview and DPA, plus direct paths to our infrastructure providers' own trust portals (Railway, Netlify, PostHog, and others), where their attestation reports are available first-hand.

Scroll to Top