Security
Security.
Effective September 11, 2026. Plain, factual, and nothing we can't back up.
MarketHQ is a small product, and this page says exactly what we do — not more. We don't claim certifications or audits we haven't actually gone through.
How we protect data
- Encryption in transit. All traffic to and from MarketHQ runs over HTTPS/TLS.
- Database hosting. The database is a managed Postgres instance hosted on Railway.
- Authentication. Sign-in runs through Better Auth. Credentials are stored hashed, sessions are tracked with httpOnly cookies, and state-changing requests are checked against a trusted-origin allowlist before they're processed.
- Payment data. Card and payment details never touch MarketHQ's servers — checkout runs on Dodo Payments' hosted checkout page, and we only store the resulting subscription status and billing history.
- Webhook verification. Billing webhooks from Dodo Payments are signature-verified before we trust them, using the Standard Webhooks signature scheme.
- Secrets. API keys and other secrets are kept in environment configuration, never committed to source control.
Reporting a security issue
If you find a security issue, email manoj@markethq.ai with details and we'll respond as quickly as we can.