New piMark is a six-agent autonomous marketing team — now in private preview. Read the manifesto →
Security & trust

Autonomous doesn't mean unaccountable.

Six AI agents touch your brand's content. Here is exactly how we handle your data, isolate your tenant, control access, and keep every action reviewable — and where we're honest that we're still early.

Where we are today. piMark is in private preview. This page describes our current approach and commitments, not completed third-party certifications. Where we reference a certification, it's on our roadmap and marked as such — we won't claim an audit we haven't passed.

Our approach

Five commitments that shape how piMark is built

Tenant isolation

Every workspace's content, brand assets, credentials and audit history are logically separated by tenant. One brand's data is never used to draft, train or benchmark another's.

Encryption in transit and at rest

All traffic to and from piMark runs over TLS. Content, credentials and connected-account tokens are encrypted at rest using industry-standard algorithms.

Least-privilege access

Team members get role-based access scoped to what their job needs. Internal engineering access to customer content is logged and limited to what's required to operate or support the product.

Tamper-evident audit logging

Every agent action — a draft, a review decision, a schedule, a publish — is written to an append-only audit log with who or which agent acted, when, and why.

Kill switches at every level

You can pause a single agent, a channel, or the entire account instantly. A kill switch stops in-flight automation immediately — nothing new schedules or publishes until you resume it.

Human-in-command by default

New accounts start in full-review mode: no agent action ships without a human clicking approve. You choose if and when to loosen that, per brand and per channel.

Data handling

What piMark stores, and why

piMark stores the content, brand assets, connected-channel metadata and performance data you give it access to, so the six agents can plan, draft and measure your marketing. We don't collect more than the product needs to run.

  • Your content and brand assets are used to run your workspace — never to train a shared model or benchmark against other customers, without your explicit opt-in.
  • Connected-account tokens (for scheduling and publishing) are stored encrypted and scoped to the minimum permissions the platform requests.
  • You can export or delete your workspace data; account deletion removes content, credentials and audit history within our standard retention window. See our privacy policy for specifics.
Tenant: your-brand

Isolated content store · isolated credentials · isolated audit log

Encryption

TLS in transit · encrypted at rest

Access

Role-based · least privilege · logged

AI-specific safety

Governance built for agents, not bolted on

Six agents drafting, reviewing and scheduling content is a different risk surface than a single AI assistant. We built for that from day one.

Brand guardrails

You define tone, claims to avoid, compliance rules and no-go topics during onboarding. The Observer agent checks every draft against them before it reaches you or ships.

Human-in-command, always

Autopilot mode still runs inside the approval boundaries you set — it never grants an agent authority you haven't explicitly given it, and you can revoke that authority at any time.

No training on your data without consent

We do not use your content or brand data to train shared models unless you opt in. If that changes, it will be an explicit choice you make, not a default we ship quietly.

Foresight is directional, and we say so

Foresight's synthetic-audience predictions are a pre-publish gut-check, not a validated forecast. The product labels it that way everywhere it appears, including in this sentence.

Cost ledger and rate limits

Every LLM call an agent makes is logged against a per-brand cost ledger with configurable limits, so autonomous activity can't run away from your budget unnoticed.

Bounded publishing permissions

One-click publish to a channel only works after you connect that account via OAuth and grant the specific scopes it asks for. Rolling out per channel — see the integrations page for current status.

SOC 2 Type IIRoadmap
ISO 27001Roadmap
Data processing agreement (DPA)Available on request
Encryption in transit & at restLive
Compliance roadmap

We haven't earned a badge yet — here's the plan

piMark has not completed a SOC 2 or ISO 27001 audit. We're building the controls those frameworks require as part of the product's core architecture, and we'll pursue formal certification once we have the customer volume and maturity to justify it properly, not just to put a badge on this page.

If your team needs a data processing agreement or has specific security requirements before piloting piMark, tell us on your demo call — we'll work through it directly.

Have security questions before you pilot piMark?

Bring your security team's questions to the walkthrough. We'd rather answer them upfront than lose your trust later.

Talk to us