Skip to content

Nothing goes live until you approve it.

Security at Marline starts with control: agents that ask before they act, access that starts read-only, and a log of everything. Here is how it is being built, and where it stands today.

Status

Marline is pre-launch. We have not completed a SOC 2 audit or any certification.

No badges here until they are earned. Questions: founders@marline.dev

Where things stand

Marline is pre-launch. We have not completed a SOC 2 audit or any certification. No customer store is connected yet, so there is no customer store data to hold.

What follows is how the product is being built, written down now so you can hold us to it. When something here changes, this page changes with it.

Approval gates

Agents stage changes. People approve them. Anything that spends money, changes a live listing, or reaches a customer or supplier in a new way stops and waits for a person, with the reasoning and the numbers attached.

These gates are not settings an agent can change. Graduating a low-risk task to run on its own is a decision you make, task by task.

Read-only first

Every connection starts with read access. Agents learn how your store runs before they are allowed to change anything. Write access is asked for later, by name, for the specific job that needs it.

Least-privilege access

Each agent gets only the access its job needs.

  • The listings agent can't touch ad budgets. The ads agent can't edit listings.
  • Access is requested per channel and per job, and shown to you before you grant it.
  • You can revoke any connection from the channel's own settings at any time, and from Marline.

Every action in one log

Every action is written to one activity log: what changed, who did it (an agent, Claude, or you), when, and why. Approvals, edits, and rejections are logged with the reasoning that came with them. The log is meant to be read by a person, not just stored.

Autonomy you can take back

A task runs on its own only after it passes evals on real past decisions and a run of your reviews, and only within a written scope. Taking autonomy back is one action, and the task returns to asking you before each run.

Data handling

The principles Marline is being built on:

  • We store what the agents need to do the work: your catalog, inventory counts, orders, ad and listing data, and the activity log. Nothing more by default.
  • We will not sell your data, or share it for anyone's advertising.
  • Your data is deleted on request. Write to us and we will confirm when it is done.
  • Judgment calls are made with Claude, by Anthropic. Other model providers used for high-volume work will be named here before launch.

This website

This site is static pages hosted on Cloudflare, plus one small server function for the listing fixer’s live rewrite. That function holds the model API key, so no key ever reaches your browser, and it caps how often anyone can call it. The site runs no analytics and no ad trackers, and our code sets no cookies. The waitlist form opens your email app, so nothing is sent until you press send.

Reporting a security issue

If you find a security issue in this site or anything Marline runs, email founders@marline.dev with the subject “Security report”. Include what you found, how to reproduce it, and how to reach you.

We will reply, keep you updated while we fix it, and credit you if you want. Please give us reasonable time to fix an issue before you share it, and don't access data that isn't yours. There is no bug bounty program yet.

Questions about how it works?

Ask anything about access, data, or approvals. Every message goes to the founder.