Secure transport
Marrova.com uses HTTPS with an actively managed TLS certificate and redirects unsecured requests.
Least privilege
Credentials and provider access should be scoped to the smallest practical capability.
Human control
Sensitive outbound actions require explicit authorization and traceable ownership.
Honest status
Preview and planned protections are not represented as completed certifications.
Protection on the public Marrova site.
- HTTPS enforced for marrova.com and www.marrova.com.
- Canonical host redirects reduce duplicate and spoof-like URLs.
- Browser security headers restrict framing, content-type guessing, and device permissions.
- No payment-card, password, or client-record collection on the marketing site.
- Contact and demo requests use the established Marrova support address.
Report a possible security issue privately.
Email support@marrova.com with “Security report” in the subject. Include the affected URL, what you observed, and safe reproduction steps. Do not access, alter, or share data that is not yours.
Marrova does not currently claim SOC 2, ISO 27001, HIPAA, PCI, or other formal certification on this site. Formal assurance claims will be published only when they are true and verifiable.