MarkGrid · Legal
Security
Last updated: September 17, 2026
Security is a first-class design constraint at MarkGrid. Below is an overview of our platform security posture. Enterprise customers receive a full security pack including penetration test summaries and incident response procedures as part of contract diligence.
Platform security
Customer data is encrypted at rest with AES-256 and in transit with TLS. Each customer's data is kept separate by row-level security enforced in the database itself, not only in application code. Access to production systems is restricted to authorized team members.
Application security
We follow a secure SDLC: peer-reviewed code, static analysis on every pull request, dependency scanning, and independent third-party penetration testing. Critical vulnerabilities are patched within 24 hours of validated disclosure.
Infrastructure
MarkGrid's primary database runs on Supabase's managed infrastructure on AWS in the Sydney, Australia region (ap-southeast-2), with a replica in the same region. Credentials for connected advertising accounts are encrypted with AES-256 before storage, using keys held outside the database. Secrets are never written to source code.
Compliance
We operate aligned to ISO 27001 controls, GDPR, and the India DPDP Act. A signed DPA is available on request.
Responsible disclosure
We welcome security research. Submit findings to security@markgrid.ai with reproduction steps. We commit to acknowledge within one business day and to coordinate disclosure responsibly.
Looking for our security pack, or want to schedule a security review with our team? Email security@markgrid.ai.
This document is intended as a plain-language summary for prospective customers. Enterprise customers receive the full executed legal documentation as part of the contract pack. For any conflict between this summary and an executed agreement, the agreement controls.
