Skip to content

Trust centre

Sensitive business data deserves quiet, explicit boundaries.

This page explains the safeguards implemented in the product and the limits that remain. MarginKoala does not claim certifications it has not earned.

Current posture

Reviewed 28 August 2026

Read-only by default

Initial business-data connectors read evidence. They do not move money, issue refunds or change a source system.

Encryption with a precise scope

Traffic uses HTTPS/TLS. Connector credentials use an AES-256-GCM application vault and opaque references; they are not added to AI prompts.

Bounded AI handling

AI requests use the relevant context selected for the task. Gateway requests require zero data retention and disallow prompt training; enabled direct fallback requests set storage off.

Export and supported deletion

Owners can request a bounded account export. Account deletion revokes connector credentials and removes tenant-owned product records through the supported closure path.

Managed recovery boundary

Production uses managed database backups and a documented restore path. Recovery checks are kept separate from live customer workflows.

Redacted operations

Structured telemetry is designed around routes, stages, outcomes and opaque account hashes, not raw prompts, documents, credentials or unnecessary financial payloads.

The implemented retention schedule

Different records have different purposes. “Account life” means MarginKoala does not currently apply a shorter automatic time-based purge to that category. This is the deployed technical schedule, not a claim that every legal retention decision has received final counsel approval.

Koala files, extracted candidates and temporary analysis context

30 days

Deleted by the authenticated daily retention job, or sooner through a supported deletion path.

Organisation membership audit

730 days

Deleted in bounded batches after its retention expiry.

Authentication sessions

Up to 7 days of validity

Can be revoked sooner; password reset and account closure revoke the applicable sessions.

Invitation and shared-report access

14 days for team invites; 1–30 days for report links

Access expires or can be revoked sooner. The related account audit record can remain for the account life.

Profiles, calculations, chats, decisions, tasks, reports and connected facts

Account or organisation life

No shorter automatic purge; removed by the relevant product control or supported closure workflow.

Billing reconciliation and closure controls

No shorter automatic application expiry

Direct identifiers are removed where supported; bounded pseudonymous records can remain to stop late provider events recreating access.

Redacted operational and aggregate telemetry

Configured operator/provider retention

No universal shorter application expiry; raw prompts, documents, secrets and unnecessary financial payloads are excluded by policy.

Recovery copies

Seven daily managed points; seven-day encrypted off-site artifact when enabled

Deleted account data can remain until the applicable recovery copy expires. Restores follow the documented reconciliation procedure.

Read the operational privacy notice

Named service and subprocessor inventory

Inclusion here does not mean every optional service is active for every customer. A provider receives data only when its feature is enabled and used. Whether a provider is legally a processor, independent controller or another category depends on the service and contract; this page does not manufacture that classification.

Vercel

Application hosting, delivery, server-side functions and AI Gateway routing.

Core hosting; AI Gateway only when Koala invokes a configured model.

Supabase

Managed PostgreSQL infrastructure and managed database backups.

Core production data and recovery boundary.

Stripe

Checkout, subscription billing, invoices, payment methods and refunds.

Only for billing features; full card details stay with Stripe.

Resend

Transactional account, security, billing and support email.

Only when a transactional message is requested or scheduled.

OpenAI, Anthropic and Google

Configured AI model processing selected through the routing policy.

Only the provider selected for a Koala request receives its bounded context.

Tavily and Perplexity

Current public-information research.

Only when enabled and a question maps to the closed public-topic vocabulary; Perplexity is an optional fallback.

Rutter, Nango and Basiq

Optional read-only connector transport and, for Basiq, Australian CDR/Open Banking.

Only for a connection the customer authorises and the operator has activated.

Google and Microsoft

Optional account sign-in.

Only when the customer chooses that sign-in method.

Better Stack

Redacted operational error delivery and operator alerting.

Only when the production monitoring destination is configured.

Google Analytics 4 and Meta Pixel

Optional public-site acquisition measurement.

Disabled unless the owner configures the service and the applicable consent boundary permits it.

Service health and uptime

MarginKoala exposes a machine-readable current health boundary. It reports current service readiness, not historical uptime and not a contractual service level.

Current service health

No separate public historical-status page is currently published. Production errors and alerts route to the configured operator monitoring path.

Incident lifecycle

  1. Detect and record a privacy-safe correlation identifier.
  2. Contain the affected provider, connector or feature with the narrowest available kill switch.
  3. Assess scope without copying customer payloads or credentials into the incident record.
  4. Remediate safely; use a forward fix when an already-committed database change cannot be rolled back safely.
  5. Verify service, tenant isolation, data integrity and monitoring before restoring the path.
  6. Notify affected people and authorities when the assessed facts and applicable obligations require it, then record closure and follow-up.

Report a security or privacy concern

Include enough detail to identify the affected account or event, but never send a password, API key or full payment-card number by email.

Contact support