Security

How to tell us, and what we actually do.

Short, because it only contains things that are true.

Reporting something

Email help@margo.global with enough detail to reproduce it. It is a shared mailbox, so put “security” in the subject — the mailto link above does that for you.

We have not agreed a response time and will not claim one. Someone reads it.

We will not take legal action against someone who investigates in good faith, tells us privately, and does not access other people’s data or degrade the service.

What this website does

  • Every page is served over an encrypted connection (HTTPS), and browsers are told never to use an unencrypted one.
  • A strict content security policy, with a fresh one-time value on every request, so your browser will not load code, styles or fonts from anyone but us.
  • Every form is checked again on our own server, and so is every address this site answers on. The browser is never trusted to enforce a rule.
  • Each form carries a one-time value that we check when you submit it, so another website cannot submit the form in your name.
  • A limit on how often forms and checkout can be submitted from one place.
  • Passwords and keys stay on our server. None of them are sent to your browser.
  • Errors that do not echo back what you typed, and logs that do not contain form contents, email addresses or payment identifiers.
  • No card details touch our servers. Stripe collects them directly.
  • Messages from our payment provider are accepted only when they are correctly signed, recorded once, and applied in the order they were sent.

What the app does

  • On the Mac, your records are files in your home directory, under your own macOS account’s permissions.
  • The copy your iPhone needs is held by Margo’s account service, reached only over an encrypted connection, and only after you sign in.
  • The key that pays for the AI is never on your Mac or your iPhone. It stays inside Margo’s own AI service.
  • Margo can read your Google Calendar and Google Tasks but cannot change them. Gmail is optional: Margo reads the headers of a message — the sender, the subject, the date — and the preview line, never the full message, and sends an email only when you press Send. No Google Drive.

What we do not claim

  • No SOC 2, ISO 27001, HIPAA or GDPR certification. None of those have been audited.
  • No penetration test — nobody paid to try to break in — has been carried out.
  • Not end-to-end encrypted. What syncs between your devices travels over an encrypted connection, but Margo’s account service can read it.
  • We do not pay for reported security bugs. We have no money to run such a programme honestly.
  • No claim that the software is secure in any absolute sense. It is young code, and saying otherwise would be a marketing sentence rather than a security one.

The current build is version 1.0 and is notarized and signed with a Developer ID certificate. What that means for installing it.