MARS Security
Legal

Privacy Policy

Mars “Send to Mars” Splunk add-on (TA-mars-alerts)

Effective date: 28 May 2026 · Last updated: 28 May 2026

This Privacy Policy explains how Mars Security (“Mars”, “we”, “us”, or “our”) collects, uses, and protects information in connection with the Mars “Send to Mars” Splunk add-on (the “Splunk App”). For the in-product Mars platform itself (app.marssec.ai), a separate, customer-facing privacy notice applies and is provided to each customer under contract.

If you have any questions about this policy, contact us at mars-support@marssec.ai.

1. Who we are

Mars Security operates the Mars threat-hunting and detection engineering platform, and the Mars Splunk App that integrates with it. The data controller for the purposes of this policy is Mars Security. You can reach our privacy contact at mars-support@marssec.ai.

2. Scope of this policy

This policy applies to the Mars 'Send to Mars' Splunk add-on, covering the information the add-on forwards to Mars and how Mars handles it. It does not cover the authenticated Mars platform at app.marssec.ai, which is governed by your organization's contract with Mars and its associated customer-facing privacy notice. It also does not cover Splunk itself, which is operated by you and governed by your agreement with Splunk.

3. Information we collect from Splunk

The Splunk App is a custom alert action that runs inside your Splunk environment. The App itself is outbound-only: it does not connect back to, authenticate against, or query Splunk — it only sends data outward to Mars. Through the App, Mars receives data only when a saved search you have explicitly configured with the “Send to Mars” action triggers. On each such trigger, Mars receives:

  • Alert results. A capped subset of the matching rows from the saved search (the true total match count is also reported). These rows contain whatever fields your search returns, which may include personal or identifying data such as usernames, email addresses, IP addresses, or hostnames, depending on how your search is written.
  • Search context. The search query (SPL), the saved search name and description, the owner, the schedule, the time range, and a link back to the results in Splunk.
  • Severity. The alert severity on Splunk's 1–5 scale, either the saved search's configured value or a per-action override.
  • Delivery credential. A Mars-issued webhook token, sent by the add-on to authenticate each delivery. The token is generated in Mars and stored encrypted inside your Splunk configuration; Mars retains it to validate inbound deliveries.

Scope of the Splunk App. The App does not run searches, does not read any data other than what a triggered, configured saved search forwards, and does not receive anything back from Mars. You control which saved searches forward data and what those searches return.

4. How we use information

We use the information above strictly to:

  • Ingest the forwarded alert into your Mars tenant so it can be used in your security workflow (for example, as an input to threat hunts).
  • Authenticate and attribute each delivery to the correct Mars tenant using the webhook token.
  • Operate, secure, and troubleshoot the service, including investigating misuse or abuse.
  • Comply with legal obligations.

We do not use your data for advertising, profiling unrelated to security investigations, building external products, or training general-purpose AI models. We do not sell your data.

5. Lawful basis for processing (EEA / UK)

Where the EU/UK General Data Protection Regulation applies, our lawful bases are: (a) performance of a contract with your organization, (b) our legitimate interests in operating and securing the service, and (c) compliance with legal obligations.

6. How we share information

We share information only with trusted subprocessors. A full list is available on our sub-processors page. Categories include:

  • Cloud infrastructure providers (e.g., Amazon Web Services) for hosting, storage, and networking.
  • LLM providers (e.g., OpenAI, Anthropic, Azure OpenAI) used by Mars's investigation and hunting agents.
  • Operational tooling such as error monitoring and logging providers.

We do not share your data with third parties for their own marketing or advertising purposes.

7. How we protect information

Mars applies industry-standard safeguards including TLS in transit, encryption at rest, tenant-scoped handling of the webhook token, least-privilege access controls, audit logging, and regular security review of code and dependencies. The add-on delivers to Mars over HTTPS with a bearer token.

8. Data retention

  • Webhook token is retained until you revoke or rotate it in Mars, or until your contract with Mars ends, whichever comes first.
  • Forwarded alert payloads (results, SPL, severity, metadata) are retained as operational records for up to 90 days by default, then automatically deleted, except where they have been incorporated into hunt or investigation outputs.
  • Hunt and investigation outputs are retained according to your organization's contract with Mars and are governed by the in-product privacy notice.

You can request deletion at any time by emailing mars-support@marssec.ai.

9. Your rights

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: request deletion of your data, subject to legal retention obligations.
  • Portability: request a copy of your data in a machine-readable format.
  • Objection / restriction: object to or restrict certain processing.

To exercise any of these rights, contact mars-support@marssec.ai.

10. International data transfers

Mars and its subprocessors operate in multiple regions. Your data may be processed in jurisdictions other than the one you live in. Where required, we rely on appropriate safeguards (such as the EU Standard Contractual Clauses) for cross-border transfers.

11. Children's privacy

Mars is a B2B security product and is not intended for individuals under 16. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, by notice through the Mars platform. Continued use of the Splunk App after an update constitutes acceptance of the revised policy.

13. Contact us

Questions, requests, or complaints can be sent to mars-support@marssec.ai.

14. Governing law

This policy and any disputes relating to it are governed by the laws of the State of Israel, without regard to its conflict-of-laws principles. Nothing in this policy limits any non-waivable rights you may have under applicable local law.

MARS Security © 2026
SOC 2AWS Marketplace