ISO 27001:2022
Information security management: how client data is classified, stored and moved, who can reach it, and how we respond when something goes wrong.
UKAS-accredited certification body · Certificate No. 24112
Security and trust
Marella is built and operated by OpenKit Ltd, which holds ISO 27001, ISO 9001 and Cyber Essentials. This page covers what is built into the product, what depends on how you deploy it, and how to get the evidence your review needs.
Information security management: how client data is classified, stored and moved, who can reach it, and how we respond when something goes wrong.
UKAS-accredited certification body · Certificate No. 24112
Quality management: how work is scoped, reviewed, documented and improved, so a handover holds the same standard whoever does it.
UKAS-accredited certification body
Baseline technical controls on our own systems: patching, access control, malware protection and secure configuration.
National Cyber Security Centre scheme
The certificates are held by OpenKit Ltd, company number 13030838. We send current files, scope statements and renewal dates to your compliance team on request.
Every workspace is scoped to your organisation. A document is either private to whoever added it or shared across your organisation, and you choose which.
Accounts support TOTP two-factor authentication.
A citation opens the document at the page and passage it came from, so you can check the answer against the source before you rely on it.
After an answer is generated it is checked against its sources, and inaccurate citations and unsupported claims are flagged.
Decision traces record what an agent did and why. They are not a log of every user action, and we list the events they cover in the evidence pack.
The product's legal terms state that customer data is not used to train Marella or the configured AI providers.
Where documents are stored, which providers run inference, who can reach support and how long records are kept all follow from the route you choose.
We run it. The fastest route to a working deployment, with storage and inference paths documented for your review.
Marella runs in your own cloud accounts, so your existing agreements and controls apply to the infrastructure.
A packaged deployment you run on infrastructure you choose, operated by your own team.
Before anything goes live we write down the split of responsibilities for your chosen route: what the product handles, what depends on how it is hosted, and what your team runs.
Certificates are held by an organisation, not by software. OpenKit Ltd, the company that builds and operates Marella, holds ISO 27001:2022 (UKAS-accredited body, Certificate No. 24112), ISO 9001:2015 and Cyber Essentials. We send the current files, scope statements and renewal dates to your compliance team on request.
No. The product's legal terms state that customer data is not used to train Marella or the configured AI providers. We confirm provider and subprocessor coverage for your chosen deployment as part of the review.
It depends on the route you choose. Managed, your-cloud and self-hosted deployments have different storage, inference and support paths, and we document them during architecture review rather than making one universal claim.
OpenKit Ltd operates to UK GDPR and the Data Protection Act 2018. For your deployment we document where data lives, who can reach it and how erasure works, and your organisation stays the controller.
Access is scoped to your organisation, and each document is either private or shared to the organisation, and you decide which. Where a connector inherits permissions from a source system, we test that inheritance for your integration before it goes live.
Send the questions your due-diligence process asks through the form below, and tell us which deployment you are considering. We reply within one working day with what is available now and what needs a scoped technical answer.
Send the questions your due-diligence process asks: certification scope, architecture, subprocessors, or who is responsible for what. We reply within one working day.
Keep this form non-confidential. We will agree a secure way to send questionnaires and documents after the first reply.