Security

MarginTrace connects to production revenue, product, cost, and support systems. These are the controls that apply to that access.

Least-privilege connections

Every connector requests the narrowest scope that supports the advertised result. Help-desk access begins read-only. Write access is granted per action and only after an authorized user approves it.

Workspace isolation

Connected records, identity maps, and computed outputs are scoped to the workspace that connected them. Row-level access rules are enforced in the database, not only in the application.

Support Operator separation

Support Operator runs on a separate application and database from the analytics products. It has separate help-desk OAuth credentials, connector secrets, action-policy engine, ticket content, audit events, usage meter, and permissions. Only aggregate commercial events enter the shared marketing analytics layer.

Audit trail

Every automated resolution retains retrieved sources, account observations, tool calls, policy decisions, confidence, the final response, and any human correction. Every analytics change retains the rule, the operator, and the timestamp.

Emergency stop

Support Operator exposes a persistent control bar with mode, eligible issue classes, allowed actions, confidence threshold, escalation owner, and an emergency stop that halts automated responses immediately.

Reporting a vulnerability

Send findings to security@margintrace.com.