AI Dispatch
The wirewireSep 23, 2026

Ad-management agent GoMarble AI says its SOC 2, ISO 27001 and GDPR compliance work is still "in progress"; requires approval before executing changes

The company's security page lists three compliance frameworks as unfinished and pledges not to train AI models on customer data.

GoMarble AI, an agent that connects to advertising platforms including Meta, Google Ads and TikTok, lists its compliance status directly on its security page: "SOC 2 Type II In progress ISO 27001 In progress GDPR In progress," according to the page, retrieved Sept. 19. A fourth listed standard is marked "OAuth Best Practices Aligned" rather than in progress — the page distinguishes between work still underway and work it says is done.

On data use, the company states "customer data is never used to train GoMarble or third-party AI models." GoMarble also says it "has completed business and app verification with Google, Meta, and Shopify" for the advertising accounts its agent connects to, and that authorization to those accounts "uses OAuth 2.1 with PKCE (Proof Key for Code Exchange) to protect authorization codes against interception."

On runtime governance, a separate page states: "Nothing changes until you say yes. GoMarble shows the reason, the exact edit, and the expected effect. You approve the move" — meaning changes to a customer's ad campaigns require an explicit human sign-off before they execute.

Neither the security page nor the product page mentions insurance, an indemnification clause or a liability cap. GoMarble's compliance disclosure stands out for naming specific unfinished work rather than staying silent or claiming a certification outright: three named frameworks, each marked as not yet complete. That leaves the company scored on governance and pending compliance, with no public position yet on insurance or outcome settlement — the dimensions that determine financial responsibility if an approved automated change to an ad account causes a loss.

Entries in this piece 1

Published index entries backed by the same source documents this piece cites.

Sources 7

  1. SOC 2 Type II In progress ISO 27001 In progress GDPR In progress
    www.gomarble.ai · checked Sep 19, 2026
  2. OAuth Best Practices Aligned
    www.gomarble.ai · checked Sep 19, 2026
  3. Customer data is never used to train GoMarble or third-party AI models.
    www.gomarble.ai · checked Sep 19, 2026
  4. GoMarble has completed business and app verification with Google, Meta, and Shopify.
    www.gomarble.ai · checked Sep 19, 2026
  5. Authorization uses OAuth 2.1 with PKCE (Proof Key for Code Exchange) to protect authorization codes against interception.
    www.gomarble.ai · checked Sep 19, 2026
  6. Nothing changes until you say yes. GoMarble shows the reason, the exact edit, and the expected effect. You approve the move.
    www.gomarble.ai · checked Aug 7, 2026
  7. GoMarble analyzes Meta, Google, TikTok, Microsoft Ads, GA4, Shopify, Klaviyo, and more together in one place.
    www.gomarble.ai · checked Aug 7, 2026