Under the hood: What privacy actually looks like with Mark, Optimizely's AI

Leah MessengerLeah Messenger
8. Okt. 2026

Two Optimizely builders explain exactly what happens when you connect a system to Mark, Optimizely's AI — what's logged, what's scoped, and what never happens at all.

A few weeks ago, two people on our team each tried a buzzy new personal AI assistant (names undisclosed, for reasons our legal team would call “sensible”); the kind that promises to read your email, your calendar, your messages, and finally get you.

One person lasted about five minutes before disconnecting it. The other gave it a full day before deciding it wasn’t worth it either.

Neither account was about the tool being broken. It worked fine. It’s that having access to everything about someone didn’t make the output any better — it just made the risk bigger for no real payoff. More access, but not more value, which is basically the whole privacy conversation happening around AI right now.

Enterprises ask about it in every connector conversation we have. So we got specific with the two people who built the approach to data and access within Optimizely’s AI, Mark: Imran Yousuf, VP of Software Engineering, and Alex Whitney, Principal Product Manager.

Here’s what actually happens when you connect a system to Mark.

TL;DR, for the skimmers (it’s cool, we like skim-reading too)

  • What’s a connector? An API wearing a name tag.
  • What can it actually see? Exactly what you could already see. Not more.
  • Does anyone know what it did with my data? Yes, every call’s logged, and you’re allowed to go look.
  • Can an agent take over my browser? No. We never built that door.
  • Can IT turn specific tools off? Yep, before anyone on the team even sees them on the list.
  • Can I connect my own tools too? Also yes, bring your own MCP.

 

What a connector actually is

Connector is one of those words that means something different depending on who’s using it, and in AI, that ambiguity causes real confusion.

It’s a tool, and a tool is a wrapper around an API you were already using. When Mark connects to Salesforce, Gmail, or Teams, it authenticates with the same credentials and hits the same endpoints a person would use logging in directly. Nothing new gets exposed; the interface is just conversational instead of a UI you click through.

The tools — when we call it a tool, it is nothing but a wrapper or an API. It is still the same APIs that you’re calling.

Imran Yousuf|VP of Software Engineering

That distinction gets missed constantly, because people trust “API” (something they’ve used for twenty years) and are wary of “AI tool” (something that feels new). It’s the same risk surface, wearing a different name.

How access gets scoped

Access in Mark is scoped to you. Connect your own Teams account and you see the chats you’re already in — not every conversation at the company. Connect Gmail and you’re scoped to the inbox you authenticated with, exactly as if you’d logged into gmail.com yourself. No new data gets created by the act of connecting; if you couldn’t see something before, connecting a tool doesn’t change that.

There’s a less obvious effect too: connecting a tool actually reduces the amount of data moving around, compared to the alternative. If you were already planning to paste an email thread into a chat window for help with it, that data was leaving its original system either way — you were just moving it manually, with no record of who else might see the copy-paste. A connector replaces that with a scoped, auditable action.

Most people do not actually correlate that you are not introducing any new surface area. You are actually reducing the surface area, in a certain way.

Imran Yousuf|VP of Software Engineering

Not a new door. The same door, with a record of who walked through it.

What gets logged, and who can see it

Most AI products can’t tell you what they did with your data during a session. Mark keeps an execution log of every tool call — across agents and regular chat — and makes it inspectable. That’s not an agent-only feature bolted on for enterprise; it’s logged the same way no matter how you’re using Mark.

When you are going to use any other AI, you will have zero visibility in there. The good thing with Mark is that every transaction, every call is actually saved and is available for user review.

Imran Yousuf|VP of Software Engineering

For a buyer evaluating the platform, that’s the difference between being told to trust the system and being able to verify it themselves.

Why Mark won’t let agents drive your browser

One deliberate architecture choice: Mark doesn’t let agents control a live, stateful browser session. Some AI tools let an agent log into a site and operate inside that session directly, which means once you’ve logged in, what happens next is out of your hands. The session exists outside any single, auditable action.

Mark intentionally made a choice of not allowing agents to use a browser directly — not in a stateful manner.

Imran Yousuf|VP of Software Engineering

Mark keeps everything inside the path of a tool call instead: authenticated through OAuth, scoped to a specific action, logged, and revocable at any time. Disconnect a tool and the access ends immediately — there’s no lingering session to account for.

Admins decide what’s available before anyone touches it

Control starts further upstream than the individual connection. Admins can enable or disable specific tools within a connector at the instance level, before anyone on the team can connect to anything — unlike most platforms, which ship an integration with every tool switched on by default.

If they’re like ‘I never want anybody to touch Gmail tools’, then just toggle them off before you install the tools. And they’re not even in the platform.

Alex Whitney|Principal Product Manager

An admin can keep Google Calendar available while switching Gmail off entirely, so it’s not even an option on the list. For teams working under strict data-handling rules, that’s often what makes adoption possible at all.

What happens to your data after the call ends

Mark only works with LLM providers running on Optimizely’s own cloud infrastructure, under a zero-data-retention agreement — the providers don’t store or train on anything that flows through them. Delete an execution log or a file, and it’s gone. Not hidden. Gone.

The important aspect isn’t whether we’re storing the data. It’s whether you have insight into what we’re storing — and control to delete it, at any point in time you want to.

Imran Yousuf|VP of Software Engineering

Bring your own MCP

Mark ships with a growing, curated set of built-in connectors for enterprise marketing workflows, but it’s not a closed list. Customers can connect their own MCP servers and get the same OAuth-based, per-user access model applied to systems Mark didn’t build a dedicated integration for.

Security isn’t a special case reserved for Optimizely-built connectors. It’s the standard every connection runs through.

The takeaway

Enterprises don’t ask about data privacy because they distrust AI as a category. They ask because they’ve seen what happens when a system accumulates access faster than anyone tracks it.

Enterprise requires control. Consumer apps — people just don’t think about it, and they give it up.

Alex Whitney|Principal Product Manager

Mark’s answer isn’t “trust us”; it’s a specific, inspectable set of guarantees: access scoped to what you already have, every call logged, admin control over what’s even available, and a flat no on training. Not the flashiest story to tell about AI. It’s the one enterprise teams need answered before they’ll connect anything at all.

Want to find out more about Mark and Optimizely Agent Platform? Head to optimizely.com/ai.