Market Dog . AIMarket Dog . AICreate an account

Trust

Security at Market Dog . AI

How we protect your documents and your team's data. This page is an overview; for detailed security questions, contact support.

Our principles

  • Default-deny access — nothing is shared more widely than it needs to be.
  • Defence in depth — checks in the application and at the data layer.
  • Keep secrets out of source — credentials live in managed encrypted storage.

Tenant isolation

Every document is scoped to a workspace, company, and project. Cloudflare D1 does not provide row-level security, so Market Dog . AI enforces tenant isolation in its application services with authenticated user and workspace checks on every data operation. Requests outside the authorised scope are rejected.

Encryption

Data is encrypted in transit with TLS and encrypted at rest by our infrastructure provider. Secrets such as AI provider keys are held in dedicated encrypted storage, never in plain configuration.

Authentication

Sign-in is handled through a managed identity provider. Sessions are short-lived and tied to the active workspace, and access can be revoked centrally.

AI input handling

Content sent to a language model is sanitised and wrapped with a per-request boundary before it leaves Market Dog . AI. User content is never concatenated into a trusted system prompt, which reduces the risk of prompt injection.

Least-privilege access

Members only see the companies and projects they are assigned to. Administrative actions are limited to workspace administrators.

Operational practices

We keep audit logging, backups, and change control in place as standing controls. Dependencies are scanned for known vulnerabilities as part of our build pipeline.

Reporting a vulnerability

If you believe you have found a security issue, please email security@marketdog.ai with the details. Please do not publicly disclose the issue until we have had a chance to investigate and respond.