Designed to Keep Your Data Secure

Connects AI to your marketing stack using industry-standard security practices and official platform APIs

The GoMarble glass marble protected inside three precise concentric access rings.
Industry Standard Encryption
No AI Training on Customer Data
Secure OAuth Authentication
Monitoring & Auditing Logs
Encrypted Secrets Management

Verification & secure connections

GoMarble has completed business and app verification with Google, Meta, and Shopify. Other native connectors use their platforms' official authorization flows.

Google

Completed OAuth app verification and brand verification, with a privacy policy hosted on verified domains and linked from the OAuth consent screen.

Meta

Completed Meta business verification with official business documentation, following Meta's data and privacy requirements.

Shopify

Meets Shopify App Store requirements for data privacy and security, with secure handling of protected customer data.

Klaviyo

Uses OAuth 2.0 with PKCE and requests read-only access to connected lifecycle and customer data.

LinkedIn Ads

Uses LinkedIn OAuth and requests advertiser, reporting, and organization permissions through LinkedIn's consent screen.

Bing Ads

Uses Microsoft Advertising OAuth with the platform's management permission and offline access.

TikTok Ads

Uses TikTok Business OAuth to connect the advertiser accounts you authorize.

Compliance & Standards

We're continuously investing in our security program and aligning GoMarble with industry best practices.

STANDARDSTATUS
SOC 2 Type IIIn progress
ISO 27001In progress
GDPRIn progress
OAuth Best PracticesAligned

What GoMarble does - and doesn't do

What we do

Securely connect to your marketing platforms

Use official APIs and secure authentication methods to connect with platforms like Meta, Google Ads, Shopify, and more.

Protect your credentials

Encrypt access credentials and securely manage them using dedicated secrets management infrastructure.

Execute AI workflows

Analyze data, generate recommendations, and execute actions through connected platforms based on the workflow's approval settings.

Monitor and log platform activity

Maintain audit logs, monitor platform health, and follow incident response procedures to support secure operations.

Give you control over your data

Allow you to disconnect integrations, revoke access, delete reports, conversations, and your workspace whenever you choose.

What we never do

Train AI models on your business data

Customer data is never used to train GoMarble or third-party AI models.

Access your accounts without authorization

GoMarble only connects to platforms that you've explicitly authorized.

Store more data than necessary

Marketing performance data is processed to generate insights and isn't permanently stored unless you explicitly save it.

Bypass your workflow settings

Automation follows the rules you've configured, whether that means requiring approval or allowing autonomous execution.

Share customer data across organizations

Each workspace's data remains isolated and is processed only to deliver the requested functionality.

Platform-Specific Access

GoMarble connects using official APIs and requests the permissions required for the workflows you enable

Read access

View and analyze authorized data without changing it.

Write access

Create or update authorized objects through enabled workflows.

All access

Bundled read and write limited to the accounts and assets you authorize.

PlatformConnection grantWhat it covers
Meta Ads
Provider permissions: pages_show_list, pages_read_engagement, read_insights, instagram_basic, instagram_manage_insights, instagram_manage_comments, catalog_management, business_management, ads_read.Provider permissions: pages_show_list, pages_read_engagement, read_insights, instagram_basic, instagram_manage_insights, instagram_manage_comments, catalog_management, business_management, ads_management.
Read access shows accounts, campaign settings, performance, pages, insights, Instagram data, comments, and catalogs. Write access adds campaign management. The account role and your workflow settings remain the ceiling.
Google Ads
Provider permission: Google Ads API access (adwords).
Google provides one app grant for Google Ads rather than separate read-only and write grants. The connection can read reporting data and is technically write-capable; GoMarble only executes changes through enabled workflows.
Google Analytics 4
Provider permissions: Google Analytics account access and Analytics read-only data access.
Connects Google Analytics account access with read-only Data API access for analytics reporting.
Shopify
Default provider permissions in the connector: read_products and read_orders.
Reads product and order data from the stores you authorize.
TikTok Ads
Provider-authorized advertiser access.
Reads authorized advertiser accounts, campaign performance, and creative data for reporting and analysis.
LinkedIn Ads
Provider permissions include ad read, ad reporting, and ad management, together with the organization permissions shown in LinkedIn's consent screen.
The provider grant includes ad reporting and ad management permissions. Current GoMarble workflows use LinkedIn for reporting and analysis.
Microsoft Ads
Provider permission: Microsoft Advertising management access (msads.manage).
The provider's Microsoft Advertising grant is manage-capable. The current connector reads accounts, campaigns, performance, keywords, ads, budgets, and change history.
Google Search Console
Provider permission: Search Console read-only access (webmasters.readonly).
Reads Search Console properties and performance data that you authorize.
Klaviyo
Provider permissions are the read-only scopes for each listed Klaviyo resource.
Reads accounts, catalogs, campaigns, events, flows, images, lists, metrics, profiles, segments, subscriptions, tags, and templates.

Authentication & OAuth security

GoMarble authenticates using OAuth and follows the Model Context Protocol authorization specification and OAuth 2.1 best practices

OAuth 2.1 and PKCE

Authorization uses OAuth 2.1 with PKCE (Proof Key for Code Exchange) to protect authorization codes against interception.

Token security

Uses short-lived access tokens, refresh-token rotation for public clients, secure token storage, and HTTPS-only authorization endpoints.

Standards-based discovery

Supports OAuth 2.0 Protected Resource Metadata and Authorization Server Metadata for secure, standards-based endpoint discovery.

MCP-compliant

GoMarble's MCP Server adheres to the MCP OAuth authorization specification, including Dynamic Client Registration.

Security architecture & operations

Encryption and credentials

Customer data and integration credentials are encrypted in transit and at rest using industry-standard encryption.

Monitoring and audit logs

Continuous monitoring of infrastructure and services, operational activity logged for troubleshooting, and alerting.

Infrastructure

Network segmentation, least-privilege access controls, and regular vulnerability assessments.

Backups and recovery

Regular backups help protect customer data and support recovery.

Secure development

Security-by-design principles across the development lifecycle, security-focused code reviews, input validation, and rate limiting.

Questions about security?

Need a security review, compliance information, or have questions about how GoMarble protects your data? Our team is happy to help.

Mail Us →