Legal
Security
Last updated: June 22, 2026
We take the protection of business and customer data seriously. This page describes the security measures in place today and the improvements we are planning.
Markly is in a pilot phase. We describe only controls that exist today and clearly separate planned improvements.
Current controls
- All traffic is served over encrypted HTTPS/TLS connections.
- Platform data is hosted on managed infrastructure (Vercel and Neon) that provides encryption at rest.
- Authentication uses established providers (Google, Apple, Microsoft) and email sign-in links.
- Session tokens are cryptographically signed.
- Role-based access controls separate business owners, staff, and Markly HQ.
- Tenant isolation: each business's data is scoped to that business.
- Customer self-service links use random, hashed tokens.
- Markly HQ access is restricted to an internal allowlist, and HQ impersonation actions are recorded in an audit log.
- Operational and lifecycle events are logged for monitoring and troubleshooting.
Planned improvements
- Field-level encryption for selected sensitive fields and integration tokens.
- Expanded self-service data export and deletion tools.
- Cookie consent management.
- Formalized data-retention automation.
- Independent security assessments.
What we do not claim
- Markly is not currently SOC 2, ISO 27001, or HIPAA certified.
- Markly does not claim GDPR certification.
- Markly does not provide end-to-end encryption.
To report a security concern, contact imark3020@gmail.com.