Trust
Security and privacy for webhook data.
Webhook bodies carry PII and payment metadata. Marevans is designed so that data stays in your account, in your region, under keys you manage - with fewer third-party processors in your DPIA.
Summary
Controls that map to how teams actually deploy.
Your infrastructure
Compute, storage, and network resources run in VPCs or clusters you own. Marevans does not receive webhook payloads.
Encryption
TLS 1.2+ on ingress and to destinations. Data at rest encrypted with keys from your cloud KMS or HSM.
Least privilege
Service accounts scoped to secrets, queues, and storage the gateway needs. No blanket admin.
Auditability
Immutable delivery history per event, exportable logs, and optional SIEM integration.
Data flow
Where data goes - and where it does not.
A straight line from provider to your network, with no Marevans-operated datastore in the middle.
- The provider sends HTTPS POST to your Marevans ingress (load balancer, API gateway, or ingress controller you operate).
- Marevans verifies signatures and writes the event to encrypted storage in the same region.
- Delivery workers call your internal services over TLS inside your network (or via private connectivity).
- Telemetry (metrics and logs) can stay in your account or forward to your observability vendor - your choice.
Marevans the company provides software updates and licensing. It does not operate a multi-tenant cloud that stores your payloads.
Internet → ingress (your cloud) → Marevans → encrypted store ↓ internal services (billing, etc.)GDPR
GDPR and data residency considerations.
Deploying in the EU keeps receipt, storage, and delivery in-region. You remain controller; Marevans is not a processor of payload content.
For many teams, the critical question is whether another vendor becomes a processor of personal data in webhooks. With self-hosted Marevans, payload processing happens on infrastructure you control. You still must assess lawful basis, retention, subprocessors (your cloud provider), and DPA terms with your cloud provider - Marevans does not replace legal review.
- Deploy in eu-west-1, eu-central-1, or other EU regions
- Redact or drop personal fields before storage with JSON-path rules
- Separate payload and metadata retention to limit exposure over time
- Export or delete events using admin APIs for erasure requests (subject to your retention policy)
Questions for your DPO? Contact us for a security questionnaire or architecture review call.
Roadmap
Compliance roadmap.
Self-hosted security is table stakes; we publish evidence as it becomes available to customers.
Available now
- Self-hosted deployment
- KMS encryption
- Configurable retention and redaction
- EU and US regions
In progress
- SOC 2 Type II (Marevans company)
- Penetration test summary for customers
- Signed SBOM with releases
Planned
- HIPAA-aligned deployment guide
- FedRAMP-oriented reference architecture
Need a security review pack?
We can share architecture diagrams, data-flow notes, and questionnaire answers for procurement.