Certified & compliant
Your data is in safe hands.
Markin works inside the customer data of some of Europe's largest B2C businesses and launches actions in the systems they already run. That runs on certified controls, EU data residency and governance you can audit line by line.
Last updated: August 2026

Certified on both halves of what we do.
Independent certification covers how we protect information, and how we build and operate agentic AI that acts on your customers.
ISO 42001
Certified AI governance framework, customers see exactly how we build and run agentic AI.
ISO 27001
Fully certified against the internationally recognized standard for information security.
SOC 2 Type II
Independent audit of the controls securing customer data across every system Markin runs.
GDPR
European technical team, EU data residency, and zero training on customer data by default.
Trusted data storage
- EU data residency
- Customer data is stored and processed in EU regions, and our engineering team operates from Europe under EU law.
- Encrypted end to end
- All traffic runs over TLS 1.2 or higher and data at rest is encrypted with AES-256, with key rotation handled by the platform.
- No foundation model training
- Your behavioural and transactional data is never used to train shared or third-party models. Anything that learns from it stays inside your tenant.
Enterprise-grade security
- Zero trust by design
- No user or service is trusted implicitly. Every request to production is authenticated, scoped to the least privilege that works, and logged.
- Tenant isolation
- Each customer runs in a logically isolated environment with separate credentials, storage scopes and model artefacts.
- Access on your terms
- Engineers reach customer data only for a support issue you have approved, through time-bound access that expires on its own.
- Tested resilience
- Encrypted backups on a continuous schedule, rehearsed restores, infrastructure as code, and peer review plus automated scanning on every change.
Autonomy with a documented leash.
Markin does not only read your data, it launches actions on your customers. ISO 42001 is the framework we run that under, and the limits are yours to set.
- Explicit autonomy limits
- Each deployment declares which action types agents may launch alone, which need approval and which are off-limits, per channel and per audience.
- Human in the loop
- High-impact actions, discounts, pricing changes and anything touching a protected segment sit behind an approval step with a named reviewer.
- End-to-end traceability
- Every action traces back to the signal, hypothesis and expected value that produced it, and forward to the measured result against a holdout.
- Holdouts by default
- Actions ship with a randomised control group so impact is measured, not asserted. What does not clear the bar is retired.
- Fairness and exclusion rules
- Segments, frequency caps and exclusion lists are enforced at decision time, before an action can reach a customer.
- Kill switch
- Any campaign, agent or the whole deployment can be paused instantly, with in-flight actions stopped at the execution boundary.
Your data. Your decisions.
You keep control of your data at all times.
Where your data lives, how long it stays, who can reach it and what the agents are allowed to do with it are your settings, not ours.
Data retention
Set retention windows that match your internal policy and regulator. On termination, data is deleted or returned within the agreed period, backups included.
Data governance
A complete audit trail of who accessed what, which agent decided what, and which human approved it, exportable to your own SIEM.
Minimum data
Markin ingests the fields a hypothesis actually needs. Pseudonymous keys are used wherever a direct identifier is not required to decide an action.
User authentication
SAML SSO and SCIM provisioning give you full control over who reaches the workspace, with mandatory MFA on every internal system.
Subprocessors & reporting
A short list, published.
Markin keeps its subprocessor list deliberately small. Each vendor is reviewed before it can touch customer data, is bound by a data processing agreement, and is covered by the notification terms in our DPA when the list changes.
Security researchers can report issues to security@markin.ai. We acknowledge reports within two business days and keep you updated until the issue is closed. Customers can request our certifications, penetration test summary or a completed security questionnaire at the same address.
FAQ
- Which security certifications does Markin hold?
- Markin is certified against ISO 27001 for information security and ISO 42001 for AI management systems, holds a SOC 2 Type II report, and operates in compliance with the GDPR.
- Where is Markin customer data stored?
- Customer data is stored and processed in European Union regions, and Markin's engineering team is based in Europe.
- How does Markin encrypt data?
- All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Integration credentials live in a managed secret store, scoped per tenant and per connector, and are never written to logs or model prompts.
- Does Markin train models on customer data?
- No. Customer data is never used to train shared or third-party foundation models. Any model that learns from your data is scoped to your tenant only.
- Can Markin take actions on customers without human approval?
- Only within limits you set. Each deployment declares which action types agents may launch autonomously; high-impact actions such as discounts or pricing changes sit behind a named approver, and everything can be paused instantly.
- What happens to our data if we stop using Markin?
- You can request a full export before the contract ends. After that, customer data and any dedicated storage tied to your deployment are deleted within the period agreed in the DPA, backups included.
Serious about security?