Trust · Security
Security at MarketStand
A short summary of how we handle your data. For the detailed program, request our security packet from security@marketstand.com.
Compliance
MarketStand is SOC 2 Type II. Our auditor's report and our subprocessor list are available under NDA — email security@marketstand.com.
Data handling
Customer data is encrypted in transit (TLS 1.2+) and at rest. Production access is restricted to a small on-call group, gated by SSO and hardware keys, and every access is logged.
We collect the minimum needed to run the operator — see the privacy policy for the full list.
Subprocessors
We use a small number of vendors: Stripe (billing), SendGrid (transactional email), PostHog (analytics and error monitoring), and our hosting provider. Each handles only the data needed to perform its function.
Reporting an issue
Found a vulnerability? Email security@marketstand.com. We acknowledge reports within one business day and don't pursue researchers acting in good faith.