Your catalogue, your prices and your buyers' data deserve bank-grade care. This is how OctoMarkets is built:
All traffic runs over TLS; data is stored encrypted in managed European data centres, including encrypted backups.
Systems talk to each other via shielded service accounts; staff work with personal accounts, strong passwords and two-factor authentication. Access is logged and reviewed periodically.
Test and production environments are strictly separated; customer data is never held in third-party test systems.
Our AI-built integrations are validated offline before anything at all goes to a marketplace. Errors never reach your sales channels.
A documented response policy; we report any data breaches to the Dutch data protection authority (Autoriteit Persoonsgegevens) and to the customers concerned in accordance with the GDPR.
Security researchers can report vulnerabilities via security@octo.markets. We respond within 1 working day.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU |
| DigitalOcean | Application hosting and file storage | EU |
| Vercel | Web hosting (website and portal) | EU/US (SCCs) |
| Temporal | Process orchestration (technical IDs only, no personal data) | EU/US (SCCs) |
| Hookdeck | Webhook delivery | EU/US (SCCs) |
| Postmark | Transactional email | US (SCCs) |
| Anthropic | AI processing of product data (no personal data, no model training) | US (SCCs) |
We announce changes to this list to our customers in advance. Last updated: 19 July 2026