Credentials at rest
Customer-authorized credentials live in Infisical. Human credentials and recovery material live in 1Password, not in code or agent definitions.
OperationalMarshal security posture
Marshal designs, deploys, and operates agents with authority kept narrow, credentials kept out of agents, and customers kept in control of approvals and rules.
Practical safeguards for the systems, people, and agent authority behind Marshal's Managed Agent Operations service. Select any category to see the underlying controls.
Trust is enforced through identity, credential, runtime, and recovery boundaries. Current gaps stay visible until they are closed and tested.
Customer-authorized credentials live in Infisical. Human credentials and recovery material live in 1Password, not in code or agent definitions.
OperationalEncrypted transport is required for application and administrative traffic across Marshal's managed cloud providers.
Documented commitmentCredentials are resolved for authorized work. Agents do not receive general vault access or become the durable credential owner.
Documented commitmentAutomated database backups, secrets recovery testing, and annual recovery exercises remain open work items.
In progressPolicies and Practices
We take the security of your data very seriously at Marshal. If you have additional questions regarding security, we are happy to answer them. Please write to security@runmarshal.com and we will respond as quickly as we can.
Access control, credential management, incident response, and business continuity.
Internal working assessment. Not submitted to CSA STAR.
No penetration-test or third-party audit claim is made today.
Policies and diligence material
Detailed policies and diligence materials can be shared with qualified customers upon request.
This page
Control Plane, Data Plane, and agent boundaries
Core providers and operating roles
security@runmarshal.com
Prepared for approval
Prepared for approval
Prepared for approval
Prepared for approval. Recovery objectives are not yet validated.
Internal draft. Not publication-ready.
Not yet available
Marshal uses established managed platforms for hosting, data, delivery, source control, credential management, and frontier-model access.
Composio is not currently deployed. A formal subprocessor and data-location summary will be published after deployment regions are verified.
If you believe you have found a vulnerability affecting Marshal, please report it directly. We will acknowledge the report, investigate it, and keep you informed as we work toward resolution.
Report a vulnerability