Trust at Marsen

Security starts with clear boundaries.

How to use Marsen’s public tools safely, report a security concern, and discuss controls for customer projects.

Updated 14 September 20262 min read
At a glance

The right controls depend on the data and the work. Agree access, ownership, review points, and incident contacts before connecting a customer system.

Public tool boundaries

Public-page tools are intended for publicly accessible websites. Browser calculators and pasted-answer checks run locally in the page. Never paste credentials, payment details, confidential records, or a private administration URL into a public tool.

Controls to agree for a project

Before implementation, identify who owns each connected system and what the workflow needs to read or change. The project agreement should define permissions and responsibilities.

  • Give each integration only the permissions its task requires.
  • Keep credentials in managed configuration, outside source code and public reports.
  • Define human approval for sensitive or irreversible actions.
  • Agree logging, retention, recovery, and incident contacts.
  • Review access when staff, providers, or workflows change.

Report a suspected vulnerability

Email [email protected] with the affected URL, a description, and safe reproduction steps. Use the subject “Security report”. Redact personal information and secrets. Stop testing when you have enough evidence, and do not access, change, or delete another person’s information.

Email a security report

Evidence and assurance

A security statement is not a certification. Ask for controls and evidence relevant to your proposed deployment. Hosting, authentication, encryption, monitoring, and recovery need to be verified for the actual system rather than inferred from the marketing website.