For security, legal and works-council review
Read the source, run Margince on your own infrastructure, and see every action the AI wants to take before it happens. Your Legal, your IT and your works council can verify it themselves.
The AI has two permission levels. One it uses freely. The other it can never use on its own.
The separation between the two levels is enforced in the architecture; there is no admin setting that turns it off. When the AI needs the second level, it stops and waits for a person - who sees what it wants to do, and why, before saying yes.
Reads, drafts and approvals are written to a log you own. When someone asks what the AI did with your data on the 14th, the log answers it.
Margince runs on your own servers or at a European host you choose. Your customer data is not shipped to us to make the product work. The only thing that ever leaves is an action you approved.
Hosting: your own infrastructure, a private cloud, or an EU host - DE · AT · CH.
No forced vendor model. Bring the model your security process already cleared - including a European one if everything must stay in the EU - on your own contract, with your own keys. Change model strategy later without touching the CRM.
Use a model approved by your company.
Use your own contract and credentials.
Receive the full source code. BUSL-1.1, Apache 2.0 after 24 months per release.
Run it on your infrastructure, in a private cloud or with an EU host.
Licensed under BUSL-1.1. Your engineers can read exactly how the AI is constrained, how your data moves, and how approvals happen - and audit Margince like any other supplier.
An AI that touches employees' work needs works-council approval before go-live. Margince is designed so that review can happen early, on documented facts.
A plain-language works-council handbook - what the AI reads, what it logs, what it can never do - is in preparation and ships before pilot go-live.
Margince runs on your infrastructure, so your data never leaves your control. Deletion and export are product functions, available at any time; leaving requires nothing from us.
The product is pre-launch, so there is no live monitoring dashboard to show. These are the controls built into the design, and because the source ships with the product, each one can be verified in code.
The transparency above carries most of the weight; procurement still needs the formal documents. Here they are, with their actual status.
Why there is no SOC 2: Margince runs on your infrastructure, not ours - there is no Margince cloud service to certify. The DPA covers the one place we do touch your systems: support and implementation work.
The sub-processor list stays short because your hosting partner and your AI provider are your contracts, chosen by you - they do not appear on our list, because they do not work for us. The list covers only what we touch during support.
Status shown is actual status; nothing is listed as held unless it is held.
Summary
Read the source. Run it in your environment. Review it with your works council.
Product preview · Coming Autumn 2026 · DACH