🔒

Enterprise-Grade Security & Privacy

Your customer data stays with you. Always.

Marcus AI is built with a hybrid architecture that protects both your customer data AND our proprietary technology. Zero-trust security meets full functionality.

See How It Works Talk to Security Team

Hybrid Security Architecture

Our unique deployment model ensures your customer data never leaves your infrastructure while protecting our intellectual property.

On Your Server (Your Control)

  • Marcus connector runs on YOUR infrastructure
  • All customer data stays in YOUR database
  • Reads customer information locally in real-time
  • We never receive names, balances, emails, or transactions
  • You maintain 100% data ownership and control

On Our Server (Our IP Protection)

  • Marcus's AI engine (personality, training, intelligence)
  • Receives anonymized queries: "How should I respond to a balance inquiry?"
  • Returns response templates: "Say: 'You have [BALANCE] in your account'"
  • Your connector fills in actual data from your database

The Result

You get full AI functionality without compromising data privacy. We protect our technology without accessing your customers.

Complete Transparency

We believe in showing you exactly what we can and cannot see. No hidden access, no backdoors.

What We CAN See What We NEVER See
Query types (e.g., "balance inquiry") Customer names
Response templates generated Email addresses
System performance metrics Account balances
Error logs (anonymized) Transaction amounts
Conversation volume statistics VIP levels
Feature usage patterns Deposit/withdrawal history
Betting patterns
IP addresses
Any personally identifiable information (PII)

How a Customer Query Works

See the step-by-step process that keeps your data private while delivering intelligent responses.

1
Customer asks: "What's my balance?"

Customer initiates conversation through any channel (web, Telegram, WhatsApp)

2
Marcus Connector (YOUR SERVER):

Reads customer balance from YOUR database: $1,250 • Data never leaves your server

3
Sends to our AI (anonymized):

"Generate friendly response for balance inquiry" • No customer data included

4
Our AI Server responds with template:

"You've got [BALANCE] in your account right now 👍" • Template with placeholder

5
Marcus Connector (YOUR SERVER):

Fills in: "You've got $1,250 in your account right now 👍" • Data inserted locally

6
Customer receives personalized response

Full functionality achieved without compromising privacy

Key Point: The actual balance ($1,250) never leaves your server.

Built-In Security Layers

Enterprise-grade security features protecting your infrastructure and data at every level.

Encryption

  • • TLS 1.3 for all data in transit
  • • AES-256 encryption at rest
  • • End-to-end encrypted API communication

Authentication

  • • JWT-based authentication system
  • • API key rotation support
  • • Role-based access control (RBAC)
  • • Multi-factor authentication available

Data Protection

  • • Read-only database access (configurable)
  • • Rate limiting to prevent abuse
  • • DDoS protection
  • • XSS and SQL injection prevention

Compliance Ready

  • • GDPR-compliant architecture
  • • Audit logging for all actions
  • • Configurable data retention
  • • Right to erasure support

License Protection

  • • 24-hour license validation
  • • Hardware-locked deployment
  • • Code obfuscation for IP protection
  • • Auto-deactivation on license expiry

Monitoring & Alerts

  • • Real-time security monitoring
  • • Intrusion detection system
  • • Automatic threat response
  • • 24/7 uptime monitoring

Flexible Deployment Models

Choose the deployment model that best fits your security requirements and operational needs.

Coming Soon

Self-Hosted

Custom

Best for: Maximum control, air-gapped environments

  • Entire system on your infrastructure
  • One-time license fee model
  • Updates delivered as packages
  • You control everything
  • Complete isolation
  • Setup time: 14-21 days
  • Dedicated training included
Request Info

Data Lifecycle & Retention

Understanding what happens to your data during operation and after cancellation.

During Operation

  • Customer data is read from your database in real-time
  • No customer data is stored on our servers
  • Only anonymized query patterns are logged (e.g., "balance inquiry at 3:42 PM")
  • Response templates are cached temporarily (no customer data in cache)

When You Cancel

  • Marcus connector continues until end of billing period
  • After license expires, connector deactivates automatically
  • No customer data remains on our systems (because it was never there)
  • You retain all conversation logs in your database

Conversation Logs

  • Stored in YOUR database only
  • You control retention policies
  • Can be exported or deleted anytime
  • Full ownership and access

Security Certifications & Audits

Verified security practices and regular third-party audits ensure the highest standards.

🔒

SOC 2 Type II

In Progress

GDPR Compliant

Architecture

Security Audits

Third-Party Regular

Pen Testing

Quarterly

Client Audits

Open to Requests

Frequently Asked Questions

Get answers to common security and integration questions.

Can you access our customer database?

No. Marcus connector runs on your server with credentials you control. We never receive database credentials or direct access. The connector only reads data locally and never transmits customer information to our servers.

What if we need to revoke access immediately?

You control the connector. Simply stop the service or revoke the API key — Marcus deactivates instantly. Since all customer data lives on your server, there's nothing to clean up on our side.

Do you store conversation history?

No. All conversations are stored in YOUR database. We only see anonymized query types for system improvement (e.g., "balance inquiry" without any customer details). You have full control over conversation logs, retention policies, and data deletion.

Is Marcus compliant with gambling regulations?

The architecture is designed to be compliant. We provide AI disclosure features and responsible gaming triggers. Final compliance is confirmed with your legal team based on your specific jurisdiction requirements.

What happens if your servers go down?

Your connector can queue queries and retry, or you can configure failover to human agents. Customer data remains safe on your server regardless of our service status. We maintain 99.9% uptime SLA with redundant infrastructure.

Can we audit the system?

Yes. We welcome security audits and can provide documentation, architecture reviews, and answer technical questions. We can also arrange for your security team to perform penetration testing on your deployment.

How do you protect your AI technology?

Through license validation, code obfuscation, and hardware locking. If a client stops paying, Marcus stops working. The AI engine remains on our servers, so they can't steal and resell our intellectual property. It's a win-win: your data stays private, our IP stays protected.

What about data encryption?

All communication between your connector and our AI uses TLS 1.3 encryption. Data at rest is encrypted with AES-256. API authentication uses JWT tokens with configurable expiration. We follow industry best practices for cryptographic standards.

Can Marcus work in air-gapped environments?

Yes, with our Self-Hosted deployment option (coming soon). The entire Marcus system can run on your isolated infrastructure with no external connectivity required. Updates are delivered as signed packages for manual installation.

Ready to See How It Works?

Talk to our security team or review our technical documentation