Margince

For security, legal and works-council review

Every claim on this page can be verified: in the source, in the log, on your own infrastructure.

Read the source, run Margince on your own infrastructure, and see every action the AI wants to take before it happens. Your Legal, your IT and your works council can verify it themselves.

See what to checkTalk to the teamProduct preview · Coming Autumn 2026 · DACH
01 — Action control

What the AI does on its own, and what waits for approval.

The AI has two permission levels. One it uses freely. The other it can never use on its own.

On its ownReads and drafts - reversible, and logged
  • Read the records you connected
  • Search and summarise
  • Draft emails, offers and to-dos
  • Prepare the morning brief
Only after a human yesEverything irreversible waits at the approval gate
  • Send anything to a customer
  • Change or delete a record
  • Move money
  • Anything that leaves your boundary

The separation between the two levels is enforced in the architecture; there is no admin setting that turns it off. When the AI needs the second level, it stops and waits for a person - who sees what it wants to do, and why, before saying yes.

02 — The audit trail

Every action the AI takes is logged.

Reads, drafts and approvals are written to a log you own. When someone asks what the AI did with your data on the 14th, the log answers it.

What the log answers
  • Which data the AI read, under which permission
  • What it wrote or suggested
  • Who approved it before anything happened
  • Which version or setting changed its behavior
  • How to get your data out if you leave
03 — The data boundary

Data stays on your infrastructure, or with a European host you choose.

Margince runs on your own servers or at a European host you choose. Your customer data is not shipped to us to make the product work. The only thing that ever leaves is an action you approved.

Hosting: your own infrastructure, a private cloud, or an EU host - DE · AT · CH.

04 — Model control

Model, contract and keys stay with you.

No forced vendor model. Bring the model your security process already cleared - including a European one if everything must stay in the EU - on your own contract, with your own keys. Change model strategy later without touching the CRM.

01

Model

Use a model approved by your company.

02

Keys

Use your own contract and credentials.

03

Code

Receive the full source code. BUSL-1.1, Apache 2.0 after 24 months per release.

04

Hosting

Run it on your infrastructure, in a private cloud or with an EU host.

05 — Source-available

The full source ships with the product.

Licensed under BUSL-1.1. Your engineers can read exactly how the AI is constrained, how your data moves, and how approvals happen - and audit Margince like any other supplier.

Full source under BUSL-1.1Ships with the product
Apache 2.024 months after each release
Software bill of materials (SBOM)Published at launch
06 — Betriebsrat

Built for works-council sign-off.

An AI that touches employees' work needs works-council approval before go-live. Margince is designed so that review can happen early, on documented facts.

  • Opt-in sources only - the AI reads what you connect
  • Private items stay out
  • Every read logged, with the reason it happened
  • Scope defined with your works council before go-live

A plain-language works-council handbook - what the AI reads, what it logs, what it can never do - is in preparation and ships before pilot go-live.

07 — The exit

Instance, data and code remain yours.

Margince runs on your infrastructure, so your data never leaves your control. Deletion and export are product functions, available at any time; leaving requires nothing from us.

08 — Security & privacy controls

The controls a reviewer looks for, in the architecture.

The product is pre-launch, so there is no live monitoring dashboard to show. These are the controls built into the design, and because the source ships with the product, each one can be verified in code.

Access control

By design · checkable in source
  • Role-based access to every record
  • Read seats separated from acting seats
  • Opt-in sources only - the AI reads what you connect
  • Private items stay out of scope
  • Every read logged, with the reason it happened

AI governance

By design · checkable in source
  • Human approval gate on every send, change, delete or payment
  • Unapproved actions expire; approved ones undoable for 72 hours
  • Every AI-written value carries its evidence, or is left blank
  • One governed surface - first-party tools pass the same gate, no privileged backdoors
  • Your model, your keys - no forced vendor model, no usage meter

Data protection

By design · checkable in source
  • Runs inside your boundary: on-prem, private cloud, or EU host (DE · AT · CH)
  • Customer data is never shipped to us to make the product work
  • Data residency sits in the architecture, not in a contract
  • GDPR by design
  • Nothing leaves the boundary without an approved action

Transparency & exit

By design · checkable in source
  • Full source ships with the product (BUSL-1.1, Apache 2.0 after 24 months)
  • Software bill of materials (SBOM) published at launch
  • An audit log you own: what, when, on whose behalf, who approved
  • Works-council handbook in preparation - ships before pilot go-live
  • Documented exit path: your instance, data and code stay yours
09 — The paperwork

Certifications and agreements, with current status.

The transparency above carries most of the weight; procurement still needs the formal documents. Here they are, with their actual status.

Engineering ISMS (Gradion, the builder)ISO 27001
Independently audited
Data Processing Agreement (DPA / AVV)For support & implementation engagements
In preparation
Sub-processor listShort by design
Published at launch
Signed releases + SBOMSupply-chain verification
At launch

Why there is no SOC 2: Margince runs on your infrastructure, not ours - there is no Margince cloud service to certify. The DPA covers the one place we do touch your systems: support and implementation work.

The sub-processor list stays short because your hosting partner and your AI provider are your contracts, chosen by you - they do not appear on our list, because they do not work for us. The list covers only what we touch during support.

Status shown is actual status; nothing is listed as held unless it is held.

Summary

Verify it yourself.

Read the source. Run it in your environment. Review it with your works council.

Product preview · Coming Autumn 2026 · DACH