This page is the official trust center for Marta.

Controls

Updated 27 days ago

Infrastructure Security

ControlStatus
  • Remote access MFA enforced
    The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.
  • Remote access encrypted enforced
    The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection.
  • Network segmentation implemented
    The company's network is segmented to prevent unauthorized access to customer data.
  • Unique account authentication enforced
    The company requires authentication to systems and applications to use unique username and password or authorized Secure Socket Shell (SSH) keys.
  • Data encryption utilized
    The company's datastores housing sensitive customer data are encrypted at rest.

Organizational Security

ControlStatus
  • Password policy enforced
    The company requires passwords for in-scope system components to be configured according to the company's policy.
  • Security awareness training implemented
    The company requires employees to complete security awareness training within thirty days of hire and at least annually thereafter.

Internal Security Procedures

ControlStatus
  • Backup processes established
    The company's data backup policy documents requirements for backup and recovery of customer data.
  • Incident response policies established
    The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users.
  • Incident management procedures followed
    The company's security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management according to the company's security incident response policy and procedures.
  • Monitoring, measurement, analysis
    The organization monitors, measures, analyzes, and evaluates its information security performance and the effectiveness of the information security management system.

Product Security

ControlStatus
  • Data transmission encrypted
    The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks.
  • Vulnerability and system monitoring procedures established
    The company's formal policies outline the requirements for vulnerability scanning, dependency monitoring, and production observability.