MARAIN

Security & data

Your data stays yours.

Data sovereignty isn’t a feature we bolt on — it’s the premise of the whole practice. Here’s how we handle your information.

How we work

Security by default, not by afterthought.

Your infrastructure, your keys

Where possible we build on your accounts, your cloud, and your API keys — so data and billing stay under your control, not ours.

Private & on-prem options

Sensitive workloads can run entirely on your infrastructure with self-hosted models, so protected data never leaves the building.

Redaction at the public boundary

When a workload does use a public API, PII is classified and redacted at the boundary — only what's needed crosses it.

Least-privilege access

Integrations get the narrowest scope that works. Credentials are stored in a secrets manager, never in code or chat.

Audit logging

AI and automation actions are logged, so you can see what ran, when, and on what data.

No training on your data

We don't train models on your data, and we configure providers to disable retention and training wherever the option exists.

Public vs private

We match the deployment to the data.

Not every workload needs the same treatment. Low-sensitivity work can use the frontier; regulated or privileged data stays private. Our whole approach is deciding — deliberately — which is which.

See the public → hybrid → private path →

Questions, DPAs, or a security review?

We’re happy to sign an NDA, complete your vendor questionnaire, or walk your team through how a specific system would handle data. Reach our data privacy officer at privacy.officer@marain.space.