MARAPONE
Security & Data-Handling Overview — Construction
DOC: SEC-PACK-CON
SCOPE: The hosted programs, the mobile app, enterprise tenants
CONTACT: security@marapone.com
Data flow — where documents go (and don't)
Documents are uploaded to infrastructure Marapone operates, and are read there. This is the path on every plan and in the mobile app alike — there is no configuration that keeps processing on your own machines. What the diagram does guarantee is the right-hand block: no third-party AI provider is ever in the path, and nothing is used to train a model.
Deployment models
On a laptop
localhost only · FileVault/LUKS at rest · zero outbound.
Plan DEFAULT
Our infrastructure, CA or EU · TLS in transit, encrypted at rest · one workspace per account.
Your cloud tenant ENTERPRISE
Private VPC · KMS/Disk encryption · IAM + SSO · your retention policy. Quoted as a project.
Mobile app INCLUDED
Same account, same workspace, same infrastructure as the browser programs · not air-gappable.
What never happens to your documents
No third-party LLM API calls
Our own open-weights model, on our own hardware.
No training on your data
Your documents never enter a training set, on any plan.
No pooled store
One isolated workspace per account, never merged across firms.
No cross-client sharing
Your findings, rates and award history stay in your workspace.
Said plainly, because a hosted service is by definition a place where your projects sit: it is our infrastructure holding your account's data. What that is not is a pooled lake or a training corpus. Data is deleted instantly and self-serve from your account settings — no ticket, no waiting period — and automatically 90 days after a subscription lapses.
The short version — for the reviewer who only needs this page
Marapone is a hosted service on every plan, in the browser and in the MaraponeAI app (iOS/Android, Q4 2026) alike. Documents are uploaded to Marapone-operated infrastructure to be read. It cannot satisfy an air-gap or on-premises data-residency requirement; where that is a hard contractual constraint, deployment into your own cloud tenant at the enterprise tier is the only arrangement we can offer.
| Processing location | Marapone-operated infrastructure in Canada by default; EU residency available on request at account setup. |
| Tenancy | One isolated workspace per account. The in-app assistant is scoped to that workspace only. Firm-tier seats share one workspace by design. |
| AI supply chain | Marapone's own open-weights model, running on the same infrastructure as the engines. No OpenAI, Anthropic, Google or other third-party inference API in the path. |
| Training use | None. Customer documents and outputs are never used to train any model. |
| Encryption | TLS in transit; encrypted at rest with managed keys. |
| Retention | Projects held while the account is active; 90 days after a subscription lapses, then deleted. Self-serve deletion from your account settings is instant — no ticket, no waiting period. Operational logs 30 days — they record that a job ran, not its contents. |
| Portability | PDF, Excel and CSV export at any time while the account is active, and throughout the 90-day window. |
| On-device | Auth token, your settings, and a cache of already-opened projects. No advertising identifier, no ad or analytics SDK. Camera and file access requested at point of use and revocable. |
| Billing processors | Apple App Store and Google Play as merchants of record. They hold payment details; we receive subscription status and tier. They never receive your documents. |
| Attestations | No SOC 2 or ISO 27001 today, and no completed penetration test of the service. A third-party test before general release is planned; we will publish the date it happens rather than the intention. Stated plainly so you can weigh it. |
Mobile access from the mobile app is the same hosted service and every row above applies to it. The screen changes; the data path does not.
Data-handling defaults
| Data residency | Canada (Toronto) or EU (Rome) by default. PIPEDA / GDPR-aligned. There is no on-premises option outside an enterprise deployment into your own cloud tenant. |
| Retention | You set per-document-class windows. Trial documents are deleted with the account’s workspace on request, the same as any other. |
| Deletion | Single command/UI action wipes a project's docs, embeddings, and project-specific weights. |
| Audit trail | Every query, document touched, and response logged with timestamp + user. Searchable and exportable. |
| Access control | Integrates with your identity provider (SSO); role-based; per-project namespace segregation by default. |
| Agreements | Mutual NDA on request before any documents change hands; project-specific NDA and DPA available pre-build. |
What you keep
The programs are access to a service we operate, not a copy of software: there is no source code, no model weights and no installer, because nothing runs on your machines. What is yours is your material. Every document you upload stays yours, everything the programs produce exports on demand in PDF, Excel and CSV, and you can delete the lot yourself, instantly, from your account settings. Exporting and deleting both need no ticket and no notice period.
The trade that comes with that is worth stating on a sheet your IT team will read: access depends on Marapone continuing to operate the service. If it were ever discontinued we commit to notice, a window in which exports keep working, and a refund of the unused remainder of any term paid for. If your obligation is that project documents never leave your own infrastructure, a standard plan cannot meet it — deployment into your own cloud tenant is available as an enterprise arrangement. Questions: security@marapone.com.