Security at Marketdata.ai
Built for finance, procurement, and market data teams at regulated firms.
The summary below is what buyers usually need during vendor review. For the underlying documents, ask us and we will share them directly.
Hosting and data residency
Where your data lives, and who can touch it.
- EU-primary infrastructure — your data stays in the European Union
- EU-first sub-processors, with a current list available on request
- Operated under Dutch law
Authentication and access control
How people sign in, and what happens the day they leave.
- Enterprise SSO over SAML 2.0 or OpenID Connect
- SCIM 2.0 automated user provisioning and deprovisioning from your identity provider
- Two-factor authentication, least-privilege roles, and session inactivity timeouts
- Removing or deactivating a leaver takes effect immediately — live sessions are signed out and workspace API tokens revoked — and is written to the audit trail
Encryption
How data is protected in transit, at rest, and between customers.
- Every layer that stores your data is encrypted at rest — database, uploaded documents, credentials, and backups
- Traffic encrypted in transit with TLS 1.3 — older TLS versions are refused, not merely discouraged; HTTPS enforced with HSTS preload
- Documents are encrypted with AES-256 under a key unique to each workspace; the storage provider never holds the key
- Deleting a workspace destroys its encryption key, making its stored files permanently unreadable
- Backups are encrypted before they leave our infrastructure, verified every day, and restore-verified
- Passwords stored with bcrypt; API tokens held only as salted hashes
Keeping customers separate
Isolation is enforced twice, independently, so a mistake in one layer is caught by the other.
- Every database query is automatically scoped to the workspace you are signed into
- Row-level security in the database re-checks that boundary independently across tenant-scoped tables, through a role that cannot bypass it
- Files are served only through the application, after you sign in — never by a link that points at storage
Document intake and email
You can forward invoices and contracts straight to your workspace.
- Each workspace has its own private intake address; mail to it can only ever be filed into that workspace
- Only senders you have explicitly approved are processed automatically — anything else is held for review
- Sender authenticity is checked with SPF, DKIM, and DMARC: a message that fails is never processed automatically, even from an approved sender
- Attachments and uploads are scanned for malware before they are stored, on our own infrastructure — an infected file is refused, not quarantined for someone to open later
- Every intake decision is recorded in the audit trail
Application security
How we keep the code and the running service safe.
- Peer code review and a secure development process
- Every change scanned for known-vulnerable dependencies and run through static analysis
- The production application is also tested by an independent third-party security platform — an automated, unauthenticated assessment; we do not claim a manual penetration test
- Sign-in, password-reset, and API endpoints rate-limited against brute-force attempts
- Automated monitoring alerts us to errors and security-relevant events — including any attempt to cross a workspace boundary
Privacy and GDPR
How we handle personal data and support your compliance obligations.
- Built to align with the GDPR
- Data Processing Agreement available to download right now — no account or sales call needed
- Sub-processor register in your account after onboarding, or on request during diligence
- Export or deletion of your data on request
Availability and disclosure
Uptime, and how to reach us about a security issue.
- 99.9% monthly uptime target
- Live service status at status.marketdata.ai — subscribe for incident notices
- Report a suspected security issue to security@marketdata.ai
- Security contact also published at /.well-known/security.txt
Vulnerability disclosure
We welcome good-faith reports from researchers, customers, and the community.
- Email findings to security@marketdata.ai. Include steps to reproduce, impact, and a proof of concept where practical.
- We aim to acknowledge reports within two business days and provide weekly status updates until remediation.
- Do not test against production systems that process customer data; prefer staging or coordinated testing. Avoid privacy violations, data destruction, and service disruption.
- Researchers who comply with this policy are treated as authorized testers acting in good faith. We will not pursue legal action against good-faith, scoped research, and we credit reporters with permission.
Request our security documentation
Our Data Processing Agreement is published — download it now, no account or sales call needed. Customers and prospects under evaluation can also request our sub-processor list and our authentication and SSO security review. Send your security questionnaire and we will work through it with you.