Skip to content

Security and trust

Security you can check

Marella is built and operated by OpenKit Ltd, which holds ISO 27001, ISO 9001 and Cyber Essentials. This page covers what is built into the product, what depends on how you deploy it, and how to get the evidence your review needs.

What we hold.

ISO 27001:2022

Information security management: how client data is classified, stored and moved, who can reach it, and how we respond when something goes wrong.

UKAS-accredited certification body · Certificate No. 24112

ISO 9001:2015

Quality management: how work is scoped, reviewed, documented and improved, so a handover holds the same standard whoever does it.

UKAS-accredited certification body

Cyber Essentials

Baseline technical controls on our own systems: patching, access control, malware protection and secure configuration.

National Cyber Security Centre scheme

The certificates are held by OpenKit Ltd, company number 13030838. We send current files, scope statements and renewal dates to your compliance team on request.

What's built in.

Your organisation is the boundary

Every workspace is scoped to your organisation. A document is either private to whoever added it or shared across your organisation, and you choose which.

Two-factor sign-in

Accounts support TOTP two-factor authentication.

Answers cite their sources

A citation opens the document at the page and passage it came from, so you can check the answer against the source before you rely on it.

Answers are fact-checked

After an answer is generated it is checked against its sources, and inaccurate citations and unsupported claims are flagged.

Agent decisions are traced

Decision traces record what an agent did and why. They are not a log of every user action, and we list the events they cover in the evidence pack.

Your data does not train models

The product's legal terms state that customer data is not used to train Marella or the configured AI providers.

What your deployment decides.

Where documents are stored, which providers run inference, who can reach support and how long records are kept all follow from the route you choose.

Managed

We run it. The fastest route to a working deployment, with storage and inference paths documented for your review.

Your cloud

Marella runs in your own cloud accounts, so your existing agreements and controls apply to the infrastructure.

Self-hosted

A packaged deployment you run on infrastructure you choose, operated by your own team.

Before anything goes live we write down the split of responsibilities for your chosen route: what the product handles, what depends on how it is hosted, and what your team runs.

Questions security teams ask.

Is Marella ISO certified?

Certificates are held by an organisation, not by software. OpenKit Ltd, the company that builds and operates Marella, holds ISO 27001:2022 (UKAS-accredited body, Certificate No. 24112), ISO 9001:2015 and Cyber Essentials. We send the current files, scope statements and renewal dates to your compliance team on request.

Will our documents be used to train AI models?

No. The product's legal terms state that customer data is not used to train Marella or the configured AI providers. We confirm provider and subprocessor coverage for your chosen deployment as part of the review.

Where is our data hosted?

It depends on the route you choose. Managed, your-cloud and self-hosted deployments have different storage, inference and support paths, and we document them during architecture review rather than making one universal claim.

Where do you stand on UK GDPR?

OpenKit Ltd operates to UK GDPR and the Data Protection Act 2018. For your deployment we document where data lives, who can reach it and how erasure works, and your organisation stays the controller.

Can we control who sees what?

Access is scoped to your organisation, and each document is either private or shared to the organisation, and you decide which. Where a connector inherits permissions from a source system, we test that inheritance for your integration before it goes live.

How do we get security documentation for procurement?

Send the questions your due-diligence process asks through the form below, and tell us which deployment you are considering. We reply within one working day with what is available now and what needs a scoped technical answer.

Ask us for the evidence.

Send the questions your due-diligence process asks: certification scope, architecture, subprocessors, or who is responsible for what. We reply within one working day.

Keep this form non-confidential. We will agree a secure way to send questionnaires and documents after the first reply.

Contact the Marella AI team

Please keep it non-confidential.