Encrypted from you to Marvin
Traffic is encrypted from your device to the Marvin workload doing the work, and again when we hand data to an outside provider.
Marvin protects customer research across account-isolated workspaces, encrypted handling, and controlled data routes.
Traffic is encrypted from your device to the Marvin workload doing the work, and again when we hand data to an outside provider.
Marvin does not use customer content to train models. External providers handle data under the applicable disclosed route and terms.
Each hosted account has its own research backend and persistent workspace.
For customer-selected routes, you choose the model providers, APIs, and connected services. Marvin governs its own services and its egress to agent-selected public research destinations.
While we have not yet completed an independent SOC 2 examination or ISO/IEC 27001 certification, Marvin's management assessment is that the program's design represents the highest standards for security, availability, and confidentiality. Independent examination and certification remain separate from our self-assessment, including observation of operating effectiveness over time where the selected assurance form requires it. If your organization requires a report, certificate, or walkthrough before using Marvin, let us know early. We will work directly with your security team.
We will update this page when our audit status changes.
Marvin is not designated by this package for protected health information, payment-card data, export-controlled data, or another specially regulated workload. Such use requires an express written agreement.
Read the public materials here. We share the full Information Security Program with approved customer and partner reviewers.