Infrastructure
- Hosting — Application runs on Vercel Fluid Compute in globally distributed regions with automatic TLS termination.
- Database — Managed Postgres via Neon with encryption at rest, point-in-time recovery, and daily backups. Connections require TLS.
- Isolation — Every customer's data is scoped to a logical workspace and enforced at the application layer.
Encryption
- TLS 1.2+ for every request in and out of the platform.
- AES-256 encryption at rest for the database and object storage.
- Password credentials stored as bcrypt hashes.
Authentication & access
- Sign-in is invite-only. Sales provisions accounts; there is no self-service signup.
- NextAuth-based session management with signed HTTP-only cookies and server-side JWT validation.
- Google SSO available on request. SAML / SCIM available on Enterprise.
- Least-privilege access for internal staff — production data access is gated by named-role approval and audit-logged.
Data ingest
- We only ingest public content permitted by each source platform's terms of service.
- Ingested data is deduplicated, normalized and stored per-campaign. Access is scoped to the workspace that owns the campaign.
Third-party integrations
Salesforce, Slack, Feishu, WeCom, DingTalk and WhatsApp integrations are opt-in per campaign. Credentials are stored encrypted and can be rotated or revoked at any time from the dashboard.
Vulnerability management
- Automated dependency scanning on every pull request.
- Continuous static analysis and secret detection in CI.
- Responsible disclosure — please report suspected vulnerabilities to security@market-voice.app. We aim to acknowledge within one business day.
Incident response
In the event of a confirmed data-security incident affecting your organization, we will notify designated contacts without undue delay (and no later than the timeframes required by applicable law), and provide a remediation plan.
Compliance roadmap
We follow SOC 2 Trust Services Criteria as a design reference and are actively working toward SOC 2 Type II certification. Enterprise customers can request our current internal-control questionnaire and sub-processor list under NDA.
Contact
Security questions or MSA / DPA requests?security@market-voice.app