Learn how to audit martech vendors, limit their access to sensitive data and make security part of every software purchase.
Table of Contents
Table of Contents
Spy on Any Website
Get traffic data and keyword intel on competitors instantly.
Marketers have spent years defending against hackers, but the bigger risk may come from the software marketers use. Now that research has found martech vendors routinely taking companies’ customer data, marketers must put an end to it.
That will require a sea change in how marketers think about vendors and solutions. It starts with understanding that every new integration is a security issue — not simply a software purchase. They need to apply the same discipline to approving software that they apply to approving campaigns: know what it’s supposed to do, verify that it does only that, and review it regularly.
Here are six steps to make that happen.
Step 1: Understand what you’re authorizing
Most marketers don’t think of clicking “authorize” as a security issue. But it is, and it’s a big one. The failure to do that is where the problem begins.
“When we’re talking about marketers and sales professionals, they … are not technical enough to know that there are red flags even happening that they should be aware of,” said Clark Barron, founder of Blackout.
Most marketers don’t fully understand what they’re approving when they connect a new application. The vendors pitch themselves as partners and, as long as the solution worked, marketers had no reason to question that.
Depending on the permissions granted, a vendor may gain access to CRM records, sales pipelines, customer support tickets, internal emails, and other sensitive business information. It’s also common to store employee and executive contacts in the same systems, so a single authorization can expose enterprise-scale amounts of information.
And adding AI makes those problems bigger and faster.
Connecting an MCP server isn’t just adding another tool — it’s giving an external system access to work alongside your AI environment. Before approving that connection, marketers should understand what instructions the integration gives the AI model, what information it can access, and what actions it can take. The answers to those questions are rarely visible by default, so vendors must be required to disclose them as part of the approval process. If you don’t know what’s “in the box,” you can’t know what the AI is being told to do.
Step 2: Inventory every integration
Before reviewing permissions, organizations should know which applications are connected to their marketing stack, who approved them, why they were installed, and which systems they can access. Get rid of old integrations, abandoned applications, and duplicated tools before they become security liabilities.
10X your SEO with Semrush for Enterprise.
The world’s most powerful SEO platform, purpose-built for Enterprise.
Request demo
Step 3: Ensure vendors have only the access they need
Marketers must learn to ask vendors hard questions and adopt an adversarial mindset.
“Verify first, and then trust,” said Barron. “When it comes to authorizing connections to your database, all of these vendors that are asking for access to your company’s information ask them. Push them. And actually get it in writing.”
Doing that means marketers must learn everything they can about how digital processing agreements are drafted, how they work, and what a sub-processor actually is.
“Learn about data brokerage practices and how that entire ecosystem works versus how it’s presented,” he said. “Because how it’s presented is nonsense. It’s just marketing fluff.”
Barron recommends starting every vendor review with six practical checks:
- Restrict read and write access to CRM objects such as pipelines and deals unless absolutely necessary.
- Block access to internal employee and executive records.
- Review Gmail and Outlook extensions that bridge inboxes and CRM systems.
- Monitor persistent access tokens that indicate long-term vendor access.
- Restrict access to customer support tickets and internal service records.
- Closely examine vendors that bypass official application marketplaces through custom OAuth implementations.
Step 4: Use AI to audit AI
Marketers don’t need to read-founder and chief data scientist at Trust Insights, says AI can do much of the work before security teams become involved
“So what companies, marketers, and everybody should be saying is, ‘What is in the box, and can I get a copy of it?’” he said. [Tell the vendor,] “‘You have to send me the prompts for your MCP that you’re running. You just have to.’ It’s part of governance.”
He recommends using the OWASP Top 10 for Large Language Model Applications as the baseline for evaluating every AI integration. “Ask your security team about it, Google it, and get it off the internet. And that is your checklist for ‘Is this thing risky?’”
Penn says marketers can also use AI to review vendor documentation against security checklists and then forward the results to security teams.
“If you don’t have a security team of any kind, this at least gets you like 70% of the way there. It helps you eliminate the obvious risks.”
Step 5: Make security part of every software purchase
Marketing teams can’t evaluate new software on their own because it requires skills and knowledge they don’t have. Every application that connects to CRM systems, AI platforms, or customer data should be reviewed by marketing, information security, procurement, and legal before it’s approved.
That review doesn’t need to slow down software adoption, but it should answer a consistent set of questions. What data will the application access? What permissions is it requesting? Does it use subprocessors? If it’s an AI integration, what instructions are built into its MCP server? If those questions can’t be answered, the software shouldn’t be connected until they can.
Step 6: Make vendor audits continuous
Installing an application must be the beginning of governance, not the end.
Permissions change. Terms of service change. Vendors add new features. MCP servers evolve. Software updates introduce new capabilities and new risks. There must be a system to regularly review every connected application, confirm that its permissions remain appropriate, remove unused integrations, and require vendors to explain any changes before expanding access to company data.
The bottom line
Marketing software is a critical part of business infrastructure. It deserves the same level of oversight as finance systems, HR platforms, and enterprise applications.
As Clark Barron said, “Verify first, and then trust.”
Penn says marketers now have everything they need to follow that advice.
“There is no excuse now, given today’s agentic tools, the smartest models we have, open weights models, and deep research tools. There is no excuse for any marketer to install unsafe software anymore without at least a cursory audit with things like the OWASP Top 10 LLM risks.”
MarTech is owned by Semrush. We remain committed to providing high-quality coverage of marketing topics. Unless otherwise noted, this page’s content was written by either an employee or a paid contractor of Semrush Inc.
Google’s “preferred sources” feature allows users to customize their search results by selecting news outlets they want to see more often in the “Top Stories” section.
