Security
Your business data, API credentials, and team account access are protected by enterprise-grade security controls. This page covers our practices, responsible disclosure program, and how to reach our security team.
API Key Management
Publishable and secret API keys are scoped per role. Secret keys are never exposed client-side. Rotate keys at any time from your account settings.
Team Access Controls
Role-based permissions for owner, admin, and employee accounts. Revoke access instantly when team members leave. Audit log of all account actions.
Business Data Isolation
Your order history, PO data, pricing agreements, and customer records are logically isolated from other business accounts. Encrypted at rest.
Payment Security
PCI-DSS Level 1
Our payment processors are PCI-DSS Level 1 certified. Market Express never stores raw card numbers.
3D Secure 2.0
Supported on all card transactions. Provides an additional layer of authentication for high-risk purchases.
Tokenization
Payment methods are stored as secure tokens with our payment processors — never on Market Express servers.
Fraud Detection
Transactions are screened for fraud by our payment processor. Unusual activity triggers manual review before fulfillment.
Securing Your Business Account
- ✓Use a unique password not shared with other services
- ✓Assign the minimum necessary role to each team member
- ✓Review active sessions under Account → Security regularly
- ✓Rotate your API keys if you suspect they have been exposed
- ✓Enable login notifications so your team is alerted to new sign-ins
Responsible Disclosure
We welcome reports from security researchers who discover vulnerabilities in our platform. Please follow these guidelines to ensure a coordinated and responsible disclosure process.
In Scope
- ✓marketexpress.us and all subdomains (www, business, buyersclub, government, dobusiness, marketing, vendors, admin, api, auth, status)
- ✓Market Express iOS and Android mobile applications
- ✓Market Express APIs (authenticated and unauthenticated endpoints)
- ✓Authentication and authorization systems
- ✓Payment processing and checkout flows
- ✓Vendor portal and admin panel
Out of Scope
- ✗Third-party services (Stripe, PayPal, FedEx, USPS, FusionAuth)
- ✗Social engineering or phishing attacks against Market Express staff
- ✗Denial of service (DoS/DDoS) attacks
- ✗Automated scanning without prior written approval
- ✗Physical security of data centers or offices
- ✗Issues already reported by another researcher
Safe Harbor
If you make a good-faith effort to comply with this policy during your security research, we commit to the following:
- ✓We will not pursue civil or criminal action against researchers who follow these guidelines
- ✓We will acknowledge receipt within 2 business days
- ✓We will keep you informed of our progress toward resolution
- ✓We will credit you in our acknowledgements (unless you prefer anonymity)
Report a Vulnerability
Email our security team with a description of the issue, steps to reproduce, and potential impact. Please do not publicly disclose until we have had a chance to address it.
security@marketexpres.us
PGP key available on request
Response within 2 business days · Mon–Fri 8am–6pm PT
What to Include in Your Report
- •Description of the vulnerability and its potential impact
- •URL, endpoint, or component affected
- •Step-by-step instructions to reproduce
- •Screenshots, logs, or proof-of-concept (no live exploit code)
- •Your name / handle for acknowledgement (optional)