MarkBook Store policy

Security

Factual safeguards for store payments, access links, fulfillment, and administration.

Payments and secrets

Card entry is hosted by Stripe. The store keeps provider identifiers and order state rather than full card numbers. Setup, invitation, access, and download tokens are random, purpose-bound, expiring, redacted from stored email HTML, and stored as hashes.

Application safeguards

The store uses HTTPS, HSTS, frame denial, restrictive permissions, content-security policy, same-origin mutation checks, rate limiting, no-store customer responses, signed webhooks, authenticated admin actions, and immutable audit events.

Fulfillment safeguards

Fulfillment jobs have idempotency keys, bounded leases, retries, dead-letter state, and reconciliation. Private Windows assets use expiring storage authorization, release metadata, and audited grant revocation.

Reporting

Report suspected vulnerabilities privately to support@markbook.com with enough detail to reproduce the issue. Do not access, alter, or retain other users' information while testing.

Certification statement

This page does not claim SOC 2, ISO 27001, or another certification. Any future certification claim must identify the entity, scope, standard, and current evidence.

Questions or accessibility requests: support@markbook.com