Security
We sell proof. We hold ourselves to it.
A content-protection product has no business overclaiming its own security. Here is exactly what we do today — no more, no less.
Encryption in transit
All traffic between your browser and iMARQd is encrypted with TLS. We enforce HTTPS across the platform with HSTS.
Encryption at rest
Content and account data are stored encrypted at rest on our infrastructure providers.
Vetted infrastructure
iMARQd runs on Vercel and Supabase — infrastructure providers that maintain SOC 2 Type II compliance and undergo regular independent audits.
Your data stays yours
We never sell your data, and we never use your protected content for anything other than providing the service to you.
Least-privilege access
Production access is restricted and credential-controlled. Secrets are managed through environment-level configuration, never in code.
Security headers
The platform ships with a strict Content Security Policy, X-Frame-Options, and related browser protections enabled by default.
What we don't claim
iMARQd itself does not currently hold SOC 2 or ISO 27001 certification — those are on our roadmap as the company grows. If your organization requires a security questionnaire or specific documentation before adopting iMARQd, email security@imarqd.com and we'll work through it with you directly.
Responsible disclosure
Found a vulnerability? Tell us.
Report security issues to security@imarqd.com. We aim to acknowledge reports within 24 hours, and we follow coordinated disclosure — we'll work with you on a fix and credit you if you'd like.
Protecting your account
- Use a strong, unique password for your iMARQd account.
- Only access iMARQd at imarqd.com and app.imarqd.com — be wary of lookalike domains.
- Keep your browser and devices updated with security patches.
- If something about your account looks wrong, contact us immediately.