Last updated · 2026-07-01

Security

How we protect the data automotive brands trust us with.

Infrastructure

  • Hosting — Application runs on Vercel Fluid Compute in globally distributed regions with automatic TLS termination.
  • Database — Managed Postgres via Neon with encryption at rest, point-in-time recovery, and daily backups. Connections require TLS.
  • Isolation — Every customer's data is scoped to a logical workspace and enforced at the application layer.

Encryption

  • TLS 1.2+ for every request in and out of the platform.
  • AES-256 encryption at rest for the database and object storage.
  • Password credentials stored as bcrypt hashes.

Authentication & access

  • Sign-in is invite-only. Sales provisions accounts; there is no self-service signup.
  • NextAuth-based session management with signed HTTP-only cookies and server-side JWT validation.
  • Google SSO available on request. SAML / SCIM available on Enterprise.
  • Least-privilege access for internal staff — production data access is gated by named-role approval and audit-logged.

Data ingest

  • We only ingest public content permitted by each source platform's terms of service.
  • Ingested data is deduplicated, normalized and stored per-campaign. Access is scoped to the workspace that owns the campaign.

Third-party integrations

Salesforce, Slack, Feishu, WeCom, DingTalk and WhatsApp integrations are opt-in per campaign. Credentials are stored encrypted and can be rotated or revoked at any time from the dashboard.

Vulnerability management

  • Automated dependency scanning on every pull request.
  • Continuous static analysis and secret detection in CI.
  • Responsible disclosure — please report suspected vulnerabilities to security@market-voice.app. We aim to acknowledge within one business day.

Incident response

In the event of a confirmed data-security incident affecting your organization, we will notify designated contacts without undue delay (and no later than the timeframes required by applicable law), and provide a remediation plan.

Compliance roadmap

We follow SOC 2 Trust Services Criteria as a design reference and are actively working toward SOC 2 Type II certification. Enterprise customers can request our current internal-control questionnaire and sub-processor list under NDA.

Contact

Security questions or MSA / DPA requests?security@market-voice.app