Trust centre
Sensitive business data deserves quiet, explicit boundaries.
This page explains the safeguards implemented in the product and the limits that remain. MarginKoala does not claim certifications it has not earned.
Current posture
Reviewed 28 August 2026
Read-only by default
Initial business-data connectors read evidence. They do not move money, issue refunds or change a source system.
Encryption with a precise scope
Traffic uses HTTPS/TLS. Connector credentials use an AES-256-GCM application vault and opaque references; they are not added to AI prompts.
Bounded AI handling
AI requests use the relevant context selected for the task. Gateway requests require zero data retention and disallow prompt training; enabled direct fallback requests set storage off.
Export and supported deletion
Owners can request a bounded account export. Account deletion revokes connector credentials and removes tenant-owned product records through the supported closure path.
Managed recovery boundary
Production uses managed database backups and a documented restore path. Recovery checks are kept separate from live customer workflows.
Redacted operations
Structured telemetry is designed around routes, stages, outcomes and opaque account hashes, not raw prompts, documents, credentials or unnecessary financial payloads.
The implemented retention schedule
Different records have different purposes. “Account life” means MarginKoala does not currently apply a shorter automatic time-based purge to that category. This is the deployed technical schedule, not a claim that every legal retention decision has received final counsel approval.
Koala files, extracted candidates and temporary analysis context
30 days
Deleted by the authenticated daily retention job, or sooner through a supported deletion path.
Organisation membership audit
730 days
Deleted in bounded batches after its retention expiry.
Authentication sessions
Up to 7 days of validity
Can be revoked sooner; password reset and account closure revoke the applicable sessions.
Invitation and shared-report access
14 days for team invites; 1–30 days for report links
Access expires or can be revoked sooner. The related account audit record can remain for the account life.
Profiles, calculations, chats, decisions, tasks, reports and connected facts
Account or organisation life
No shorter automatic purge; removed by the relevant product control or supported closure workflow.
Billing reconciliation and closure controls
No shorter automatic application expiry
Direct identifiers are removed where supported; bounded pseudonymous records can remain to stop late provider events recreating access.
Redacted operational and aggregate telemetry
Configured operator/provider retention
No universal shorter application expiry; raw prompts, documents, secrets and unnecessary financial payloads are excluded by policy.
Recovery copies
Seven daily managed points; seven-day encrypted off-site artifact when enabled
Deleted account data can remain until the applicable recovery copy expires. Restores follow the documented reconciliation procedure.
Named service and subprocessor inventory
Inclusion here does not mean every optional service is active for every customer. A provider receives data only when its feature is enabled and used. Whether a provider is legally a processor, independent controller or another category depends on the service and contract; this page does not manufacture that classification.
Vercel
Application hosting, delivery, server-side functions and AI Gateway routing.
Core hosting; AI Gateway only when Koala invokes a configured model.
Supabase
Managed PostgreSQL infrastructure and managed database backups.
Core production data and recovery boundary.
Stripe
Checkout, subscription billing, invoices, payment methods and refunds.
Only for billing features; full card details stay with Stripe.
Resend
Transactional account, security, billing and support email.
Only when a transactional message is requested or scheduled.
OpenAI, Anthropic and Google
Configured AI model processing selected through the routing policy.
Only the provider selected for a Koala request receives its bounded context.
Tavily and Perplexity
Current public-information research.
Only when enabled and a question maps to the closed public-topic vocabulary; Perplexity is an optional fallback.
Rutter, Nango and Basiq
Optional read-only connector transport and, for Basiq, Australian CDR/Open Banking.
Only for a connection the customer authorises and the operator has activated.
Google and Microsoft
Optional account sign-in.
Only when the customer chooses that sign-in method.
Better Stack
Redacted operational error delivery and operator alerting.
Only when the production monitoring destination is configured.
Google Analytics 4 and Meta Pixel
Optional public-site acquisition measurement.
Disabled unless the owner configures the service and the applicable consent boundary permits it.
Service health and uptime
MarginKoala exposes a machine-readable current health boundary. It reports current service readiness, not historical uptime and not a contractual service level.
Current service healthNo separate public historical-status page is currently published. Production errors and alerts route to the configured operator monitoring path.
Incident lifecycle
- Detect and record a privacy-safe correlation identifier.
- Contain the affected provider, connector or feature with the narrowest available kill switch.
- Assess scope without copying customer payloads or credentials into the incident record.
- Remediate safely; use a forward fix when an already-committed database change cannot be rolled back safely.
- Verify service, tenant isolation, data integrity and monitoring before restoring the path.
- Notify affected people and authorities when the assessed facts and applicable obligations require it, then record closure and follow-up.
Report a security or privacy concern
Include enough detail to identify the affected account or event, but never send a password, API key or full payment-card number by email.