Infrastructure Security
- Remote access MFA enforced
- Remote access encrypted enforced
- Network segmentation implemented
Marta brings your security policies, compliance documents, subprocessors, access requests, and trust updates into a clean, public Trust Center.
Security controls we maintain across our organization.
Our written commitments around privacy, security, and data handling.
Audit reports, certificates, and security questionnaires.
This document describes how Marta prepares for, responds to, and recovers from disruptive events that may affect the availability, integrity, or recoverability of Marta services, customer Trust Centers, customer data, administrative functionality, and supporting cloud infrastructure. It covers Marta’s business continuity governance, GCP-oriented disaster recovery approach, recovery objectives, backup and restoration expectations, communication procedures, subprocessor continuity, testing, evidence handling, and post-incident improvement process.
This document describes how Marta identifies, assesses, contains, communicates, recovers from, and learns from security and privacy incidents affecting Marta systems, customer data, Trust Center content, and related subprocessors. It outlines Marta’s public incident response governance, severity classification, response lifecycle, evidence handling, customer communication approach, GDPR-oriented breach escalation, and post-incident improvement process. This is a public version intended for customers, prospects, auditors, and partners. Detailed internal playbooks, system diagrams, detection logic, credentials, and sensitive escalation paths are intentionally omitted.
This document describes how Marta designs, builds, reviews, tests, deploys, and maintains software securely. It covers Marta’s secure software development lifecycle, secure coding expectations, source control and code review practices, secrets management, dependency and supply chain security, vulnerability remediation, environment separation, release controls, and post-release monitoring. This is a public version intended for customers, prospects, auditors, and partners. Detailed internal repository settings, CI/CD configuration, security findings, architecture diagrams, detection logic, and sensitive operational procedures are intentionally omitted.
Trusted third parties that process customer data on our behalf.
| Vendor | Purpose | Location | Data categories | Links |
|---|---|---|---|---|
| | Project management, task tracking, and team collaboration. | US | User account detailstask contentscommentsattachmentsand workspace metadata. | |
| | Content delivery network, DDoS protection, DNS, and edge compute. | Global edge network; R2 storage in EU | IP addressesHTTP request metadataCustomer filesDNS records | |
| | Managed Elasticsearch, search, and observability service. | European Union | Structured application logsHTTP request metadataAudit events | |
| | Source code hosting and collaboration platform. | United States | Source codeCI artifactsIssue and pull request metadata | |
| | Web and app analytics platform. | United States / global Google infrastructure | Pseudonymous analytics identifiersPage viewsDevice and browser metadata | |
| | Cloud infrastructure, compute, storage, and managed services. | Belgium (europe-west1) | Application dataDatabase contentsSystem logsEncrypted backups | |
| | Transactional email API for product and account notifications. | United States | Email addressesEmail contentDelivery metadata |
Quick answers to common security questions.
Reach our security team directly. We respond to vulnerability reports within one business day.