markitel
Security controls for partner integrations, broker connectivity, and browser sessions — including TLS-protected transport, server-side AES-256-GCM vault encryption, fail-closed execution controls, and traceable administrative changes.
The controls below describe how Markitel protects sensitive workflows and separates browser, partner, and provider access. Supporting policies and review contacts are available below.
Broker, payment, provider, and vault credentials are processed by server-side services. Browser clients receive only the non-sensitive configuration required to operate the product.
Content Security Policy, anti-sniffing headers, frame restrictions, and route-specific exceptions protect the standard application while supporting approved embedded widgets.
Non-essential analytics and browser error telemetry load only after consent. Visitors can review or change those preferences through the persistent cookie settings control.
Partner API keys use bearer authentication with explicit scopes. Stats and signal-feed access are separate grants, and internal signal fields are excluded from the published response shape.
Partner widgets use their own framing policy instead of loosening the whole site. Normal pages stay same-origin framed; only the embed route permits cross-origin framing.
Each external provider integration uses provider-specific credentials and independent health checks. Supported stored provider secrets are encrypted server-side with AES-256-GCM before persistence.
Markitel does not currently represent itself as SOC 2, ISO 27001, or PCI DSS certified. Certification and regulatory status will be stated only after the relevant assessment or authorization is complete and documented.
Encryption, access controls, monitoring, and least-privilege design work together to reduce risk. No internet-connected service can eliminate every security risk.
Sensitive production changes require authenticated, authorized operator actions, pre-deployment checks, and rollback procedures. Trading-critical configuration remains subject to explicit approval.
For formal vendor review, start with the documents below. Send security questionnaires and responsible-disclosure reports to security@markitel.com. Responses are based on current controls, policies, and operating evidence.
Personal-data handling, processors, retention, rights, and breach notice language.
Security practices →Responsible disclosure, security boundaries, and safe reporting instructions.
Transparency →What Markitel is, what it is not, and how to verify every claim.
Partner API docs →The server-to-server integration contract and keyed partner surfaces.
Status →Operational health and public service state.
Real-time context. Structured setups. Clearer decisions.
Start on the Free $0 plan. Eligible connection paths are confirmed separately for the provider, account, and region.
Signals are information, not investment advice. Trading involves risk of loss. Risk disclosure