Trust & Security

Enterprise grade security

Marbles protects your financial data with Australian data residency, encryption throughout, audit ready controls and independently certified security.

Read incident policy →
Certifications & audits

Independently verified

Full reports and bridge letters available on request under NDA.

CERTIFIED
ISO 27001

Information security management system certified across Covalent API Pty Ltd, the operating entity behind Marbles. Independently certified by Compass Assurance Services Pty Ltd. Certificate and scope statement available on request.

IN PRODUCTION
Enterprise grade track record

Covalent API Pty Ltd builds enterprise AI for some of Australia's largest organisations. Our clients support over 600,000 end customers. Marbles inherits the same security architecture and controls.

COMPLIANT
Australian Privacy Principles

Full compliance with the Privacy Act 1988 and the 13 APPs, including data breach notification obligations.

ALIGNED
CPS 234 aligned

Our security controls align with APRA CPS 234 information security expectations, for customers who work with regulated financial institutions.

Data residency

Where your data lives

All customer data hosted in Australia, AWS Sydney region. No data leaves Australian sovereign infrastructure except for tightly scoped subprocessors, all of which are disclosed and reviewed.

Region
AWS Sydney
ap-southeast-2, dual AZ
Residency
Australia only
No cross border data flows
Backups
Continuous
Point-in-time, 35 days
Security controls

How we protect it

The standard controls you would expect, applied to every account.

Encrypted in transit and at rest

Your data is encrypted on the way to us and while it is stored, using current industry standards.

Secure sign-in

Sign-in is handled by an enterprise grade managed identity service with secure authentication and protected sessions.

Access on a need to know basis

Team members and your accountant see only what you give them access to. You control who can view your books.

Everything is logged

Changes to your books are recorded, so there is always a clear history of what happened and when.

Backed up continuously

Your books are backed up automatically and can be restored if something goes wrong.

Regular security testing

We monitor for vulnerabilities and have our security independently tested as part of our ISO 27001 programme.

Regulatory compliance

The frameworks we meet

The obligations Marbles is engineered to meet for Australian business customers.

Framework Coverage Status
Privacy Act 1988 + APPs All Australian customer data Compliant
Notifiable Data Breach scheme 72-hour OAIC notification Compliant
ATO record keeping requirements 7-year retention, audit access Compliant
Consumer Data Right (CDR) Business disclosure model Compliant
APRA CPS 234 Control alignment for regulated counterparties Aligned
Incident handling

How we handle incidents

Security incidents are taken seriously and handled openly. Customers affected by a confirmed incident are notified within 24 hours of detection. Affected customers get a named contact and clear updates from us throughout an active event.

Detection to notification
Under 24 hours
Regulator notification
Under 72 hours (OAIC)
Post-incident report
Within 14 days