Skip to content

security

How it is run, and what is not in place yet

An agent that drafts your marketing holds your product facts, your channel credentials and your decisions. This is how that is kept, stated plainly, including the parts a larger company would have and we do not yet.

Operated by Max Zeshut. Written from the running system, as of 25 September 2026.

  1. 1. Where it runs

    One server at DigitalOcean in Amsterdam, the Netherlands. The database runs on the same server and is reachable only from inside it: its port is not published to the internet.

    The only public entry points are the website on ports 80 and 443, served over TLS with certificates from Let’s Encrypt, and SSH for administration, which accepts keys only (password login is off) and is rate-limited by the firewall.

  2. 2. One project cannot read another

    Every project is its own tenant. Each table that holds project data has Postgres row-level security forced on, and the application connects as a role without privileges to bypass it, so a query can only ever see the rows of the project it runs for. A separate test suite tries to read and write across projects against the real schema, and fails if any attempt succeeds.

  3. 3. Credentials and tokens

    • Channel credentials and model keys (a Bluesky app password, a dev.to key, a Discord webhook, your own Anthropic or Moonshot key) are encrypted with AES-256-GCM before they are stored, decrypted only at the moment they are used, and never shown back to anyone, including you.
    • MCP tokens are 32 random bytes. The database keeps only a SHA-256 hash, so a copy of the table cannot be replayed. A token is shown once, when it is made, and carries only the scopes you gave it: read, write, and approve, which is needed for decisions.
  4. 4. What the agent can and cannot do

    Every action goes through one gateway that looks up its risk class first. Drafting runs on its own; anything that leaves (a post, an email, a submission) waits for your approval or for a rule you set on that action; some actions are blocked outright and have no code path at all. An action with no policy fails closed. Money, account creation and commitments always ask. The model has a name, governed autonomy.

    Every action and every decision lands on an append-only log in which each row is hash-chained to the one before it, so an edit anywhere breaks the chain visibly. The trust page re-verifies that chain live and lists the blocked actions from the running policy table. Kill switches stop one channel or the whole agent at once.

  5. 5. Who else sees your data

    The processors are listed on the privacy page: DigitalOcean hosts the server, Brevo delivers email, and the model provider your project uses (Anthropic or Moonshot AI) receives the text it drafts from. When you connect Claude Code over MCP, the drafting happens in your own Claude session instead, on your subscription.

  6. 6. Deleting your data

    Deleting a project removes everything it owns in one step: its action log, approvals, agent runs, learnings and analytics, its published articles, and its setup (product, goal, channels, stored keys and waitlist). It cannot be undone. To have a project deleted, or a waitlist address removed, write to max@marketinque.com.

  7. 7. Not in place yet

    • No SOC 2 or ISO 27001 certification, and no audit in progress.
    • No third-party penetration test yet.
    • One server in one region, so an outage there is an outage. Live status is on the status page.
    • No single sign-on or per-user roles: a project has one owner.
  8. 8. Reporting a problem

    Write to max@marketinque.com with what you found and how to reproduce it. A person reads that inbox. Please give us a chance to fix it before you publish, and do not access data that is not yours to show the problem. The same address is in /.well-known/security.txt.

Questions about this document: max@marketinque.com.