MARS Security
Legal

Privacy Policy

Effective date: 28 May 2026 · Last updated: 28 May 2026

This Privacy Policy explains how Mars Security ("Mars", "we", "us", or "our") collects, uses, and protects information in connection with the Mars Slack application (the "Slack App") and the website at marssec.ai (the "Website"). For the in-product Mars platform itself (app.marssec.ai), a separate, customer-facing privacy notice applies and is provided to each customer under contract.

If you have any questions about this policy, contact us at mars-support@marssec.ai.

1. Who we are

Mars Security operates the Mars threat-hunting and detection engineering platform, and the Mars Slack App that integrates with it. The data controller for the purposes of this policy is Mars Security. You can reach our privacy contact at mars-support@marssec.ai.

2. Scope of this policy

This policy applies to:

  • The Mars Slack App (everything Mars does in your workspace).
  • The public marssec.ai website, including the Slack landing page and this Privacy Policy.

It does not cover the authenticated Mars platform at app.marssec.ai, which is governed by your organization's contract with Mars and its associated customer-facing privacy notice.

3. Information we collect from Slack

When your workspace installs the Mars Slack App and uses its features, Mars receives the following from Slack:

  • OAuth credentials. A bot token issued by Slack during install, used to call the Slack API on behalf of your workspace. Stored encrypted at rest.
  • Workspace metadata. Your Slack workspace (team) ID and human-readable workspace name, used to route slash commands and to display the workspace in the Mars admin UI.
  • Channel metadata. Slack channel IDs and names for channels you select as hunt-notification destinations, and for channels you reference when configuring the integration.
  • User identifiers. Slack user IDs and email addresses of users who: (a) invoke a /mars slash command, or (b) are messaged by Mars's investigation agent. Email is used solely to match a Slack user to their corresponding Mars user account.
  • Messages Mars itself sends. The content of hunt-completion summaries and validation messages that Mars posts into channels or sends as direct messages. Mars retains these for operational logging and troubleshooting.

What Mars does not read. Mars never reads message history from channels or direct messages. Mars does not request channels:history, groups:history, im:history, or mpim:history scopes. The only Slack messages Mars sees are the ones Mars itself sends.

4. Information we collect from the Website

The Website is a marketing site. We do not set tracking cookies, run third-party analytics, or fingerprint visitors. Standard server access logs (IP address, user agent, timestamp, requested path) are retained for a short period for security and operational purposes only.

The Website includes an optional contact form. If you choose to submit it, we collect and store the details you provide, which may include your name, email address, company or organization, and the contents of your message. Providing this information is voluntary, but the name and email fields are required to submit the form so we can respond to you.

5. How we use information

We use the information above strictly to:

  • Deliver the Slack App's features (post notifications, route slash commands, send analyst-approved validation messages).
  • Match a Slack user to their Mars account so commands and messages are attributed to the right person.
  • Operate, secure, and troubleshoot the service, including investigating misuse or abuse.
  • Respond to inquiries you submit through the Website contact form, including follow-up about your interest in Mars.
  • Comply with legal obligations.

We do not use your data for advertising, profiling unrelated to security investigations, building external products, or training general-purpose AI models. We do not sell your data.

6. Lawful basis for processing (EEA / UK)

Where the EU/UK General Data Protection Regulation applies, our lawful bases are: (a) performance of a contract with your organization, (b) our legitimate interests in operating and securing the service, (c) your consent when you voluntarily submit the Website contact form, and (d) compliance with legal obligations.

7. How we share information

We share information only with trusted subprocessors that help us operate the service. Current categories of subprocessors include:

  • Cloud infrastructure providers (e.g., Amazon Web Services) for hosting, storage, and networking.
  • LLM providers (e.g., OpenAI, Anthropic, Azure OpenAI) used by Mars's investigation and hunting agents. Data is sent under contractual terms that prohibit using it to train general-purpose models.
  • Operational tooling such as error monitoring and logging providers.

We do not share your data with third parties for their own marketing or advertising purposes. We may disclose information when required by law (e.g., a valid subpoena), and will challenge overbroad requests where permissible.

8. How we protect information

Mars applies industry-standard safeguards including TLS in transit, encryption at rest, tenant-scoped encryption keys for credentials such as Slack bot tokens, least-privilege access controls, audit logging, and regular security review of code and dependencies.

9. Data retention

  • Slack credentials (bot token, workspace metadata) are retained until your workspace uninstalls the Slack App, or until your contract with Mars ends, whichever comes first.
  • Operational logs (including messages Mars sent) are retained for up to 90 days by default, then automatically deleted.
  • Hunt and investigation outputs are retained according to your organization's contract with Mars and are governed by the in-product privacy notice.

You can request deletion at any time by emailing mars-support@marssec.ai.

10. Your rights

Depending on where you live, you may have rights over personal data we process about you, including:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: request deletion of your data, subject to legal retention obligations.
  • Portability: request a copy of your data in a machine-readable format.
  • Objection / restriction: object to or restrict certain processing.

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what categories of personal information we collect and to opt out of any "sale" or "sharing" (Mars does not sell or share personal information for cross-context behavioral advertising).

To exercise any of these rights, contact mars-support@marssec.ai. Where Mars is acting as a processor on behalf of your employer, we will direct you to your organization's privacy contact.

11. International data transfers

Mars and its subprocessors operate in multiple regions. Your data may be processed in jurisdictions other than the one you live in. Where required, we rely on appropriate safeguards (such as the EU Standard Contractual Clauses) for cross-border transfers.

12. Children's privacy

Mars is a B2B security product and is not intended for individuals under 16. We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Effective date" above and, where appropriate, by notice through the Mars platform. Continued use of the Slack App after an update constitutes acceptance of the revised policy.

14. Contact us

Questions, requests, or complaints can be sent to mars-support@marssec.ai.

15. Governing law

This policy and any disputes relating to it are governed by the laws of the State of Israel, without regard to its conflict-of-laws principles. Nothing in this policy limits any non-waivable rights you may have under applicable local law.

MARS Security © 2026
SOC 2AWS Marketplace