[ security ]
Built so one marketplace can never see another.
You are trusting us with your sellers, your buyers, and access to your Stripe account. This page says exactly what we do with that trust.
// isolation
Two layers between tenants.
- In the application.
- Every request is tied to one marketplace. Every query is filtered to it, and the filter cannot be switched off from application code.
- In the database.
- Row-level security is enforced on every marketplace table. The application's database role cannot bypass it.
- Tested on every change.
- An automated suite proves, for every table, that one marketplace cannot read, change, or delete another's rows.
[ stripe credentials ]
Encrypted, and never shown again.
- Encrypted with AES-256-GCM, each credential under its own key.
- Never returned by any API, never written to a log.
- The dashboard shows only the last four characters and the date added.
- Test and live credentials are stored apart and cannot be used in the wrong mode.
- Replace a credential with no downtime: add the new one, verify it, retire the old one.
// signing in
No passwords to steal.
- Sign-in is by email, with a one-time code or link that expires in 10 minutes.
- A link never signs you in by being opened. You confirm first, so a mail scanner cannot use it up.
- Two-factor with an authenticator app is available to every member.
- Sessions live in secure, HTTP-only cookies. Nothing is kept in browser storage.
[ api keys ]
Shown once, stored as a hash.
- We store only a hash of each key. The full key is shown once, when it is created.
- Keys start with
msk_test_ormsk_live_, so secret scanners can spot a leak. - Keys can be named, rotated, and revoked, and each records when it was last used.
// this website
No code on this site but ours.
The dashboard shares a domain with these pages. So no page on marketsdk.com loads a script from anyone else: no analytics, no chat widget, no tag manager, no embedded video, and no fonts from another host. A Content Security Policy enforces it.
[ data ]
We keep what you send, and nothing more.
- Identity checks run on Stripe Identity. We keep the outcome. We never keep document images or the data read from them.
- You can delete an end user's data on request.
- You can export your workspace's full data.
- Your data is never deleted because a payment failed.
- Backups are taken daily, with point-in-time recovery.
// audit
Every sensitive action is recorded.
Sign-ins, invitations, key creation and revocation, Stripe credential changes, plan changes, and any access by our staff are written to an audit log.
Found something?
Report a security issue to hello@marketsdk.com. Report a marketplace that breaks our policy to report@marketsdk.com.
- security issue
- hello@marketsdk.com
- policy abuse
- report@marketsdk.com