Program ownership
Security responsibilities, policies, and review paths are defined across the people who build and operate Surface.
Security
Our approach
Surface brings lead data, campaign execution, and marketing agents into one governed layer. Security controls are designed around the full path from connection to decision to action.
01
Security is a shared operating responsibility across Surface, not a final review added after a product ships.
Security responsibilities, policies, and review paths are defined across the people who build and operate Surface.
Confidentiality, secure data handling, access hygiene, and security awareness are part of how our team works.
We support customer diligence with questionnaires, architecture discussions, data-processing terms, and available documentation.
Our security process is designed around clear escalation, investigation, mitigation, and customer communication.
02
Surface is designed to protect customer data throughout the systems that store, process, and move it.
Connections are designed to protect data as it moves between Surface, your team, and authorized destinations.
Customer and agency workspaces are designed to keep data, settings, and execution context separated.
Operational monitoring, backups, and recovery planning are part of the controls reviewed with customer security teams.
Retention, deletion, hosting, and subprocessor questions are handled as part of the security and contractual review.
03
Access should be deliberate, limited, and removable, for both people and agents.
Connections can be scoped around the systems and actions a workflow needs instead of exposing the entire stack.
Workspace permissions help teams control who can configure connections, review work, and authorize actions.
Teams can keep sensitive actions behind review gates before an agent publishes, routes, or changes a live workflow.
Access can be removed by disconnecting systems, changing permissions, or stopping the workflow that uses it.
04
Surface agents operate inside the rules, data access, and approval boundaries your team sets.
Qualification policies, brand requirements, routing logic, and channel constraints can be defined before work begins.
Research, decisions, and generated assets can be reviewed before they reach customers or production systems.
Surface is designed to preserve the context behind agent decisions so teams can understand what happened and why.
Agents act through approved connections and workflows rather than operating outside your governed Surface workspace.
05
Security depends on the services around the product as well as the product itself.
Services that may process or support customer data are evaluated as part of the vendor approval process.
Security and operational risks are reviewed as the product, infrastructure, and vendor footprint change.
We work directly with security and legal teams to answer architecture, data handling, and contractual questions.
Current documentation and available reports are provided through the security review process.
06 · Contact and review
We can walk through Surface's architecture, data flows, agent controls, contractual terms, and currently available security documentation.
Request a security reviewBuild with confidence