Marlow holds how your organization actually works. This page explains, in plain terms, how that knowledge is protected — what we do, what our platform provider does, and what stays your responsibility.
Last updated August 1, 2026
This page is maintained by Marlow to answer common security and privacy questions about the Marlow application. It describes the controls that are in place today and is updated as the product changes.
Security is an ongoing process. As Marlow evolves, this page will be updated to reflect new capabilities and practices.
Where Marlow is today. Marlow is currently in public beta and is operated by its founder using managed cloud infrastructure. We deliberately describe what exists rather than an enterprise compliance program: there is no third-party audit, certification, or attestation behind this page, and where it describes platform capabilities those are factual descriptions of features we rely on.
Marlow runs on Lovable Cloud, a managed platform that provides hosting, a managed Postgres database, authentication, file storage, and backend functions. We do not operate our own servers, and no production data is stored on personal devices.
Every table that holds customer data is protected by row-level security in the database itself, not just in application code. That means a request can only ever return the rows the signed-in user is entitled to — even if a bug existed in the app layer.
Marlow lets you share content with someone who has no account — a contractor, an auditor, a colleague in another system — by generating a guest link. These links are deliberately narrow, and they are the one way content can be read without signing in.
Protecting operational knowledge involves both securing data and helping organizations maintain trustworthy documentation over time.
We keep our vendor list intentionally small. Current subprocessors that may process customer data on our behalf:
| Lovable Cloud | Application hosting, managed Postgres database, authentication, file storage, and backend functions. |
|---|---|
| Transactional email provider | Delivery of account, invitation, and notification emails (recipient address and message content only). |
| Stripe | Payment processing and billing for paid plans. Card details are sent directly to Stripe; Marlow never sees or stores full card numbers. |
We will update this list before a new subprocessor begins processing customer data. We do not use advertising or data-broker vendors.
Retention is summarized here and described in full in our Privacy Policy.
| Active account data | Retained while your account is active. |
|---|---|
| Account deletion | Soft-deleted for 30 days so it can be recovered, then permanently deleted within 60 days of the request. |
| Archived maps | Retained until you permanently delete them. Permanent delete is immediate and irreversible. |
| Map version history and auto-backups | Retained according to the current application configuration. |
| Audit and activity events | Retained according to the current application configuration. |
| Database backups | Approximately 14 days, rolling. |
| Support and email delivery logs | 12 months. |
| Billing records | 7 years, to meet tax and accounting obligations. |
We investigate all reported security issues as quickly as practical, based on their severity. Critical issues receive our highest priority. If we determine that customer data has been affected, we will notify affected customers and comply with applicable legal notification requirements.
If you believe you've found a security issue in Marlow, email security@makeitmarlow.com with steps to reproduce. Please give us a reasonable window to investigate and fix the issue before publishing details, and we'll work with you on disclosure timing.
We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service degradation, and do not access, modify, or exfiltrate data belonging to other users. Please do not run automated scanning that degrades service for customers, and do not test against accounts you do not own.
Security of the service is a partnership between three parties. Being explicit about which is which avoids the wrong assumption at the wrong moment.
| Our platform provider | Physical and network infrastructure, TLS certificates, database and storage encryption, patching of managed services, daily backups, and platform-level abuse protection. |
|---|---|
| Marlow (us) | Application design and code, row-level security policies, role and permission logic, secrets handling, vendor selection, retention practices, and incident response. |
| You (the customer) | Who you invite into your workspaces and at what role, who you grant map-level access to, who you send guest links to and when you switch them off, what information you choose to put into maps, keeping your credentials and devices secure, and removing access when people leave your organization. |
Questions about anything on this page? Email security@makeitmarlow.com.