Security - Where your data lives, and who can reach it.
Markular holds the roster of people working offshore: who is certified for what, who travels when, and what they are paid for. This page is the detail behind that, written for the person who has to sign off on it.

Deployment - How Markular runs
Two ways to run it. Same product and same release cadence either way.
Markular as a service
We run it for you on shared infrastructure in Azure. Nothing to set up, nothing to operate. This is how most customers run, and it is where we would start unless you have a reason not to.
A dedicated instance in your own Azure
Available on Enterprise
Your own single-tenant deployment, inside your Azure subscription. Your data sits in infrastructure you own, under your tenancy and your controls, and it does not share a database with anyone else.
We still operate it. You get the isolation without taking on the running of it, and you do not need Azure specialists on your side to keep it healthy. Updates land on the same schedule as everyone else's, so you are never left on an older version because of how you are deployed.
This is for organisations whose policy or contracts require it. If your procurement documents ask for on-premise, this is usually the answer, though it is worth checking against your exact wording: it runs in your Azure, not on hardware in your own server room.
Where your data lives
Either way, you choose the Azure region and it goes into the agreement. Most customers run in Europe North or West. If your operation needs somewhere else, we will look at what Azure offers there.
Not sure which fits? Talk to us
Privacy - You stay in control of your data.
Markular processes personnel data on your behalf. You decide what goes in and who sees it. We handle it under a signed data processing agreement, and we do not use it for anything other than running the service for you.
Who is responsible for what
You are the data controller. We are the data processor. That means we only process personal data on your documented instructions, and we say so in writing rather than leaving it implied.
Who else touches it
Five subprocessors, each for one job: Microsoft for hosting, Postmark for email, Freshdesk for support, Sveve for SMS, PostHog for product analytics. If we want to add or replace one, you get 30 days' notice and you can object.
See the full listLeaving the EEA
Data stays in your chosen region. Where a transfer to a third country is necessary, it runs on Standard Contractual Clauses.
Getting it back, or getting it deleted
When the agreement ends, we return and delete your data, and we will confirm in writing that it is done.
Read the detail: Data Processing AddendumPrivacy PolicyData Protection
Practice - We build our security programme on ISO 27001.
The same controls, documented the same way. We are not certified today.
What that looks like in practice:
Encryption
All data is encrypted at rest and in transit. HTTPS with TLS 1.2 or higher, AES-256 on the databases.
Access
Access is role based, so people see what their job needs and not the rest. You can connect your own identity provider over OIDC and let your existing sign-in rules apply.
Backups
Automatic daily backups, held in the region you chose, so a recovery does not move your data somewhere else.
Monitoring
Automated vulnerability scanning, with findings acted on as they come in rather than at the end of a quarter.
Suppliers
Every subprocessor is assessed before we use it, and reviewed while we do.
People
Everyone with access is under a continuing confidentiality obligation and is trained on handling personal data. Access is granted only where the work requires it.
Found something?
Tell us and we will look at it. We acknowledge reports within five business days.
hello@markular.com