Documents & reports
Audit reports, certificates, and security questionnaires. Request access to restricted documents below.
Documents & reports
Audit reports, certificates, and security questionnaires.
- Business Continuity and Disaster Recovery Plan
This document describes how Marta prepares for, responds to, and recovers from disruptive events that may affect the availability, integrity, or recoverability of Marta services, customer Trust Centers, customer data, administrative functionality, and supporting cloud infrastructure. It covers Marta’s business continuity governance, GCP-oriented disaster recovery approach, recovery objectives, backup and restoration expectations, communication procedures, subprocessor continuity, testing, evidence handling, and post-incident improvement process.
Request access - Incident Response Plan
This document describes how Marta identifies, assesses, contains, communicates, recovers from, and learns from security and privacy incidents affecting Marta systems, customer data, Trust Center content, and related subprocessors. It outlines Marta’s public incident response governance, severity classification, response lifecycle, evidence handling, customer communication approach, GDPR-oriented breach escalation, and post-incident improvement process. This is a public version intended for customers, prospects, auditors, and partners. Detailed internal playbooks, system diagrams, detection logic, credentials, and sensitive escalation paths are intentionally omitted.
Request access - Secure Development Policy
This document describes how Marta designs, builds, reviews, tests, deploys, and maintains software securely. It covers Marta’s secure software development lifecycle, secure coding expectations, source control and code review practices, secrets management, dependency and supply chain security, vulnerability remediation, environment separation, release controls, and post-release monitoring. This is a public version intended for customers, prospects, auditors, and partners. Detailed internal repository settings, CI/CD configuration, security findings, architecture diagrams, detection logic, and sensitive operational procedures are intentionally omitted.
Request access