OctoMarketsOctoMarkets
Trust

Security at OctoMarkets

Your catalogue, your prices and your buyers' data deserve bank-grade care. This is how OctoMarkets is built:

Encrypted, everywhere

All traffic runs over TLS; data is stored encrypted in managed European data centres, including encrypted backups.

Minimal access

Systems talk to each other via shielded service accounts; staff work with personal accounts, strong passwords and two-factor authentication. Access is logged and reviewed periodically.

Separated environments

Test and production environments are strictly separated; customer data is never held in third-party test systems.

Validate before sending

Our AI-built integrations are validated offline before anything at all goes to a marketplace. Errors never reach your sales channels.

Incident response

A documented response policy; we report any data breaches to the Dutch data protection authority (Autoriteit Persoonsgegevens) and to the customers concerned in accordance with the GDPR.

Responsible disclosure

Security researchers can report vulnerabilities via security@octo.markets. We respond within 1 working day.

Subprocessors

ProcessorPurposeLocation
SupabaseDatabase and authenticationEU
DigitalOceanApplication hosting and file storageEU
VercelWeb hosting (website and portal)EU/US (SCCs)
TemporalProcess orchestration (technical IDs only, no personal data)EU/US (SCCs)
HookdeckWebhook deliveryEU/US (SCCs)
PostmarkTransactional emailUS (SCCs)
AnthropicAI processing of product data (no personal data, no model training)US (SCCs)

We announce changes to this list to our customers in advance. Last updated: 19 July 2026