Security at Marathoon
What actually protects your data today. We would rather be precise than impressive.
Tenant isolation
Every query and every file path is scoped to your tenant, with two layers of authorization guarding the API and the data layer.
Encryption in transit
Traffic between your browser, the API, the orchestrator and the agents is encrypted with TLS. Encryption of stored files is handled by the storage provider — ours or yours.
Your storage, your rules
With bring-your-own-storage, pipeline inputs and outputs never leave your own bucket — Marathoon only orchestrates.
SSO (OIDC) & SCIM
Enterprise single sign-on through OpenID Connect and automated user provisioning, with idle sessions logged out automatically.
Granular API keys
Permission presets from read-only to full access. Keys are stored as hashes, shown once at creation and can be revoked at any time.
Encrypted credentials
Credentials you give Marathoon — storage keys, private registry access, SSO client secrets — are encrypted at rest (AES-256-GCM) with a key kept outside the database, and never displayed again. There is no managed secret store for pipelines yet.
Where we stand
Our current compliance posture, stated plainly:
- GDPR: data export and account deletion are self-service through the API, and cookie consent is granular with a 12-month retention.
- Certifications: Marathoon holds no third-party certification (SOC 2, ISO 27001) today. If that changes, you will read it in the changelog first.
- Health data: Marathoon has not been assessed for HIPAA — do not store protected health information on the hosted platform.
Data Isolation
Each tenant's data is logically isolated by our multi-tenant architecture. Your pipelines, jobs and files are separated from other customers at every layer.
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to security@marathoon.io
Questions?
For security-related inquiries, contact our security team at security@marathoon.io