Skip to main content

Security at Marketdata.ai

Built for finance, procurement, and market data teams at regulated firms.

The summary below is what buyers usually need during vendor review. For the underlying documents, ask us and we will share them directly.

Hosting and data residency

Where your data lives, and who can touch it.

  • EU-primary infrastructure — your data stays in the European Union
  • EU-first sub-processors, with a current list available on request
  • Operated under Dutch law

Authentication and access control

How people sign in, and what happens the day they leave.

  • Enterprise SSO over SAML 2.0 or OpenID Connect
  • SCIM 2.0 automated user provisioning and deprovisioning from your identity provider
  • Two-factor authentication, least-privilege roles, and session inactivity timeouts
  • Removing or deactivating a leaver takes effect immediately — live sessions are signed out and workspace API tokens revoked — and is written to the audit trail

Encryption

How data is protected in transit, at rest, and between customers.

  • Every layer that stores your data is encrypted at rest — database, uploaded documents, credentials, and backups
  • Traffic encrypted in transit with TLS 1.3 — older TLS versions are refused, not merely discouraged; HTTPS enforced with HSTS preload
  • Documents are encrypted with AES-256 under a key unique to each workspace; the storage provider never holds the key
  • Deleting a workspace destroys its encryption key, making its stored files permanently unreadable
  • Backups are encrypted before they leave our infrastructure, verified every day, and restore-verified
  • Passwords stored with bcrypt; API tokens held only as salted hashes

Keeping customers separate

Isolation is enforced twice, independently, so a mistake in one layer is caught by the other.

  • Every database query is automatically scoped to the workspace you are signed into
  • Row-level security in the database re-checks that boundary independently across tenant-scoped tables, through a role that cannot bypass it
  • Files are served only through the application, after you sign in — never by a link that points at storage

Document intake and email

You can forward invoices and contracts straight to your workspace.

  • Each workspace has its own private intake address; mail to it can only ever be filed into that workspace
  • Only senders you have explicitly approved are processed automatically — anything else is held for review
  • Sender authenticity is checked with SPF, DKIM, and DMARC: a message that fails is never processed automatically, even from an approved sender
  • Attachments and uploads are scanned for malware before they are stored, on our own infrastructure — an infected file is refused, not quarantined for someone to open later
  • Every intake decision is recorded in the audit trail

Application security

How we keep the code and the running service safe.

  • Peer code review and a secure development process
  • Every change scanned for known-vulnerable dependencies and run through static analysis
  • The production application is also tested by an independent third-party security platform — an automated, unauthenticated assessment; we do not claim a manual penetration test
  • Sign-in, password-reset, and API endpoints rate-limited against brute-force attempts
  • Automated monitoring alerts us to errors and security-relevant events — including any attempt to cross a workspace boundary

Privacy and GDPR

How we handle personal data and support your compliance obligations.

  • Built to align with the GDPR
  • Data Processing Agreement available to download right now — no account or sales call needed
  • Sub-processor register in your account after onboarding, or on request during diligence
  • Export or deletion of your data on request

Availability and disclosure

Uptime, and how to reach us about a security issue.

  • 99.9% monthly uptime target
  • Live service status at status.marketdata.ai — subscribe for incident notices
  • Report a suspected security issue to security@marketdata.ai
  • Security contact also published at /.well-known/security.txt

Vulnerability disclosure

We welcome good-faith reports from researchers, customers, and the community.

  • Email findings to security@marketdata.ai. Include steps to reproduce, impact, and a proof of concept where practical.
  • We aim to acknowledge reports within two business days and provide weekly status updates until remediation.
  • Do not test against production systems that process customer data; prefer staging or coordinated testing. Avoid privacy violations, data destruction, and service disruption.
  • Researchers who comply with this policy are treated as authorized testers acting in good faith. We will not pursue legal action against good-faith, scoped research, and we credit reporters with permission.

Request our security documentation

Our Data Processing Agreement is published — download it now, no account or sales call needed. Customers and prospects under evaluation can also request our sub-processor list and our authentication and SSO security review. Send your security questionnaire and we will work through it with you.

Questions?

Quick answers

Public info only, not your account

Ask about pricing, EU hosting, or reconciling invoices to contracts. I'm the website assistant, not the product, and I can't see your account. Want a person? Leave a work email.

Prefer a person? Reply with your work email and we'll follow up.