Autonomous doesn't mean unaccountable.
Six AI agents touch your brand's content. Here is exactly how we handle your data, isolate your tenant, control access, and keep every action reviewable — and where we're honest that we're still early.
Where we are today. piMark is in private preview. This page describes our current approach and commitments, not completed third-party certifications. Where we reference a certification, it's on our roadmap and marked as such — we won't claim an audit we haven't passed.
Five commitments that shape how piMark is built
Tenant isolation
Every workspace's content, brand assets, credentials and audit history are logically separated by tenant. One brand's data is never used to draft, train or benchmark another's.
Encryption in transit and at rest
All traffic to and from piMark runs over TLS. Content, credentials and connected-account tokens are encrypted at rest using industry-standard algorithms.
Least-privilege access
Team members get role-based access scoped to what their job needs. Internal engineering access to customer content is logged and limited to what's required to operate or support the product.
Tamper-evident audit logging
Every agent action — a draft, a review decision, a schedule, a publish — is written to an append-only audit log with who or which agent acted, when, and why.
Kill switches at every level
You can pause a single agent, a channel, or the entire account instantly. A kill switch stops in-flight automation immediately — nothing new schedules or publishes until you resume it.
Human-in-command by default
New accounts start in full-review mode: no agent action ships without a human clicking approve. You choose if and when to loosen that, per brand and per channel.
What piMark stores, and why
piMark stores the content, brand assets, connected-channel metadata and performance data you give it access to, so the six agents can plan, draft and measure your marketing. We don't collect more than the product needs to run.
- Your content and brand assets are used to run your workspace — never to train a shared model or benchmark against other customers, without your explicit opt-in.
- Connected-account tokens (for scheduling and publishing) are stored encrypted and scoped to the minimum permissions the platform requests.
- You can export or delete your workspace data; account deletion removes content, credentials and audit history within our standard retention window. See our privacy policy for specifics.
Isolated content store · isolated credentials · isolated audit log
TLS in transit · encrypted at rest
Role-based · least privilege · logged
Governance built for agents, not bolted on
Six agents drafting, reviewing and scheduling content is a different risk surface than a single AI assistant. We built for that from day one.
Brand guardrails
You define tone, claims to avoid, compliance rules and no-go topics during onboarding. The Observer agent checks every draft against them before it reaches you or ships.
Human-in-command, always
Autopilot mode still runs inside the approval boundaries you set — it never grants an agent authority you haven't explicitly given it, and you can revoke that authority at any time.
No training on your data without consent
We do not use your content or brand data to train shared models unless you opt in. If that changes, it will be an explicit choice you make, not a default we ship quietly.
Foresight is directional, and we say so
Foresight's synthetic-audience predictions are a pre-publish gut-check, not a validated forecast. The product labels it that way everywhere it appears, including in this sentence.
Cost ledger and rate limits
Every LLM call an agent makes is logged against a per-brand cost ledger with configurable limits, so autonomous activity can't run away from your budget unnoticed.
Bounded publishing permissions
One-click publish to a channel only works after you connect that account via OAuth and grant the specific scopes it asks for. Rolling out per channel — see the integrations page for current status.
We haven't earned a badge yet — here's the plan
piMark has not completed a SOC 2 or ISO 27001 audit. We're building the controls those frameworks require as part of the product's core architecture, and we'll pursue formal certification once we have the customer volume and maturity to justify it properly, not just to put a badge on this page.
If your team needs a data processing agreement or has specific security requirements before piloting piMark, tell us on your demo call — we'll work through it directly.
Have security questions before you pilot piMark?
Bring your security team's questions to the walkthrough. We'd rather answer them upfront than lose your trust later.