CLEAR INFORMATION. INFORMED CHOICES.
Security & vulnerability reporting
Security boundaries, safe reporting and account precautions.
Current boundaries
Markaigen uses HTTPS and WordPress authentication. Workspace requests check the signed-in user and ownership of saved records; public accounts do not receive administrator access. The workspace uses request nonces and rate limits. These controls reduce specific risks; they do not establish that the whole platform is penetration-tested, ISO-certified, SOC 2-audited or free of vulnerabilities.
Protect your account and data
Use a unique password and available multi-factor options, secure your email account and keep recovery methods current. Never place API secrets in public pages, screenshots or tool inputs. Upload only authorised data and keep a separate copy of important work. Pro and Enterprise labels do not imply separately audited enterprise security, SSO or a contracted service level.
Report a suspected vulnerability
Email info@markaigen.com with “Security report”, the affected URL, approximate time, a short description and safe reproduction steps. Redact secrets and personal data. Ask for a secure transfer route before sending sensitive evidence. Do not disclose the issue publicly before giving us a reasonable opportunity to assess it.
This notice does not authorise intrusive testing, account access, denial-of-service, persistence, bulk extraction or testing of third-party systems. Stop if you encounter another person’s information. There is no promised bounty or automatic legal safe harbour.
Response and incidents
We assess reports, prioritise credible risks and coordinate remediation. We do not promise a fixed resolution time for every issue. Where a personal-data breach triggers notification duties, the relevant statutory deadlines and risk assessment apply; not every technical bug is a reportable breach. For account data requests, use Privacy choices.
Questions, corrections or a request about your data?
Contact Markaigen