MarvelX Logo

Trust Center

background-image
Start your security review
View & download sensitive information
Ask for information
ControlK

Welcome to the MarvelX Trust Center. MarvelX is an Artificial Intelligence technology company specializing in building AI solutions for the financial services and insurance industries, with a focus on automation, compliance, fraud detection, and risk management. This Trust Center provides a comprehensive overview of our commitment to security, privacy, and compliance, demonstrating how we protect your data and maintain your trust.

At MarvelX, we prioritize the security and integrity of our AI-driven software solutions and the data they handle. Our Information Security Management System (ISMS) supports the development, deployment, and management of these solutions, including the information security management of client data and proprietary AI models, as well as data privacy management under GDPR and other applicable regulatory frameworks.

Our commitment to trust is evidenced by our adherence to recognized international standards and best practices. MarvelXai B.V. holds an ISO/IEC 27001:2022 certification for its ISMS, covering the development, deployment, and management of AI-driven software solutions for the finance and insurance industry, including data privacy management and processes supporting responsible AI development and deployment. We also undergo annual SOC 2 Type 1 reporting to ensure the effectiveness of our controls.

Key aspects of our trust posture include:

  • Data Protection: We employ robust encryption practices, including AES-256 with a 256-bit key for website SSL certificates, and provide information to customers about the cryptographic tools used to protect their information. We are committed to identifying and meeting requirements for the preservation of privacy and protection of Personally Identifiable Information (PII) according to applicable laws, regulations, and contractual requirements.
  • Operational Security: Our physical security measures restrict access to data center infrastructure to authorized personnel, utilizing access control systems and training for data center personnel. For cloud infrastructure, we leverage providers like AWS, GCP, and Azure, and review their attestation reports and perform risk analyses annually. We also maintain a comprehensive Vendor Management Policy, including an inventory of third-party service providers, risk assessments, and annual reviews of compliance reports and certifications (e.g., SOC 2 reports, ISO certificates) for critical vendors.
  • Employee Practices: All MarvelX personnel are subject to an Acceptable Use Policy, which includes onboarding processes, ongoing security awareness training, and strict offboarding procedures to ensure data security. Background verification checks are carried out on all candidates prior to joining the organization.
  • Continuous Improvement: Our management is closely involved in operations to identify and address any control weaknesses, ensuring legal compliance and maximizing performance. We regularly review our information security policies, rules, and standards, and conduct independent reviews of our information security approach at planned intervals.

This Trust Center serves as a central resource for understanding our security and privacy commitments in detail. We invite you to explore the various sections to learn more about our specific policies, controls, and certifications.

Documents

COMPLIANCECerti-Trust ISO 27001

Risk Profile

We have secure, reliable hosting that customers can depend on. We are happy to provide details about our risk mitigation practices and recovery objectives upon request.

Reports

We may provide security-related reports upon request.

Self-Assessments

We are working on our security compliance. We can provide completed questionnaires upon request.

AI

We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.

ESG

We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.

Legal

We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.

Security Grades

We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

Built onSafeBase by Drata Logo