The session opens.
Marzy stores credentials encrypted for your organization and retrieves them for the authorized session.
Security and trust
Vanta monitoring is live.
Before anything runs, we agree with your team on what the software can read, what it can change, and who approves it.
The trust center keeps the current documentation and the detail behind each program below.
Visit the trust centerAudit underway
An independent audit is underway. Until it’s complete, we say exactly that and nothing more. The trust center always shows the current status.
In progress
ISO 42001 is the management system standard for AI. Our work toward it is in progress, and the trust center shows where it stands.
Under a business associate agreement
Healthcare clients that handle protected health information work with us under a Business Associate Agreement. You’ll find it with the other agreements at Legal.
01
Every record carries a tenant identifier that can’t change. Forced row-level security in the database lets each customer’s sessions read and write only the rows that carry that customer’s tenant identifier. Named Mulholland engineers can reach data across customers for support, operations, and security.
02
Each service reaches the database under its own identity and the narrowest role that does its job. Administrative access needs multi-factor authentication.
03
Customer data sits encrypted where it’s stored, and it travels over TLS 1.2 or higher.
04
Under version 1.4 or later of our Master Services Agreement, we may de-identify customer data that we first receive or generate on or after the effective date of the order form or amendment by which the customer first agrees to one of those versions, and use the resulting de-identified data to train our own models, which we may sell or license. Those versions bar us from using identifiable customer data to train any model used for another customer, and from letting outside model providers, such as OpenAI and Google, train their own models on customer data or on de-identified data made from it. Customers on earlier versions keep the terms they signed.
Every write Marzy makes carries what it came from, who approved it, and when. The receipt sits next to the record it changed, not in a log line in a separate system. It only ever appends, and it outlives the person who left.
Six months later, the question is never about the software. It’s about one claim, and whether you can show who approved it.
Receipt Claim 4471, refiled
Some systems never shipped an API. Marzy works these the way a person does, in an isolated browser session, with the whole session recorded.
When something goes wrong, you don’t read a stack trace. You scrub the recording, find the mistyped field, and correct the rule that produced it.
Marzy stores credentials encrypted for your organization and retrieves them for the authorized session.
Marzy records every page, click, and keystroke, as video and as structured events, not as a log line.
Values land on the ontology object itself, not in a spreadsheet somebody has to reconcile on Friday.
The recording, the extraction, and the approval file together, as one receipt beside the record.
Session recording eligibility / nightly, 04:12
Working means a run is open. Marzy is mid-session and has filed nothing yet, and it writes nothing until the run closes.
We fit each deployment to the way your operation runs.
We agree the data connections, access permissions, and human review boundaries with your team. The engagement includes a review of the documentation and contractual commitments.
Talk through your setupYou’ll find the agreements at Legal, and every version keeps its own address. For security matters, write to security@mulholland.ai.
Read the agreements Read the policies Open the trust center