Security

Enterprise-grade security and operational governance.

Enterprise trust is foundational to the MARCO platform. MARCO is designed to support secure, explainable, and operationally governed enterprise revenue workflows.

SOC 2
Readiness · 2026 Q2
SSO
SAML · OIDC · SCIM
Human-in-loop
Approval required
US · EU
Configurable residency
Security features

Built for the controls your security team will ask for.

The same operational discipline we expect of revenue — applied to the system that serves it.

Role-Based Access Controls

Control access across teams, accounts, and operational workflows. Permissions inherit your existing org structure via SCIM.

RBAC · SCIM · SAML SSO

Audit Logging

Track operational activity and workflow actions across the platform. Immutable, exportable to your SIEM, retained per your policy.

Immutable · Exportable

Human-Controlled Execution

No CRM updates, emails, or workflow actions are executed without user approval. Every write surfaces for review and is reversible.

Approval required · Reversible

Secure Integrations

MARCO integrates securely with enterprise revenue infrastructure. OAuth scopes, IP allow-listing, mTLS where supported.

OAuth 2.1 · mTLS · IP allow-list

Explainable AI Recommendations

Every recommendation includes supporting evidence and strategic reasoning. Outputs are traceable to source signals — no black-box automation.

Source-cited · Auditable

SOC 2 Readiness

MARCO is building toward enterprise-grade compliance and governance standards. Type II audit underway with a Big-4 auditor; expected Q2 2026.

Type II · 2026 Q2
Security review · Direct

Running a security review?

We hand-walk enterprise security teams through our posture. Request a security packet — SIG-Lite, sub-processor list, architecture overview, and an open Q&A with our team.