Trust
Security
How Markyard actually keeps one print shop's data away from another's, and a plain list of what we have not built yet.
How we isolate every print shop's data
Markyard is multi-tenant: many print shops share the same database. The strongest thing we can honestly say about that is that isolation between them is enforced by the database itself, not by application code remembering to filter correctly.
Every table that holds a shop's data carries row level security with two settings on together: enable, which turns row level security on at all, and force, which keeps it on even for the table's own owner. Without force, a bug that ran a query as the table owner, for example a misconfigured admin script, would silently see every shop's rows. With it, that path is closed at the database layer, before any application code runs at all.
This is not a claim we ask you to take on faith. It is checked by an automated script in our own repository that queries the database directly and confirms, table by table, that both settings are on and that access behaves as intended, rather than a line in a document that nobody re-checks after launch.
Authentication
Markyard uses Supabase Auth for sign-up, login and session handling. Passwords are handled by Supabase Auth directly; Markyard's own code never sees or stores a plain-text password. Sessions travel in secure, http-only cookies.
Secrets and token handling
API keys and database credentials live in server-side environment variables, never in code shipped to the browser. Once Gmail connection is live, the OAuth refresh token Google issues for a connected mailbox will be encrypted before it is written to the database, using a key held outside the database itself, so a copy of the database alone is not enough to read a live token.
What we hold, and where
Markyard's database runs on Postgres, hosted by Supabase in the European Union. Our deployment target for the application itself is Vercel's Frankfurt, Germany region. AI extraction of inquiry text is performed by Google's Gemini API. See our Privacy Policy for exactly what that involves and where it sits under GDPR.
The AI boundary
Markyard's AI reads an inquiry and suggests a draft: a quote, a set of extracted details, a reply. It cannot send anything on its own. A reply goes out only after a person at your organisation clicks approve, and that requirement is enforced at the database level, not only by the interface you see, so there is no code path that skips it.
What we do not have yet
Markyard is early. Being direct about what is still missing matters more to us than sounding finished, so here is what is not true yet, stated plainly rather than left for a reviewer to find on their own.
Independent security audit
No third-party audit or penetration test has been performed on Markyard.
Formal incident response process
We do not yet have a written incident response process to link to here.
Public status monitoring
There is no automated uptime monitor yet. See the status page for the manually kept, honest version.
Compliance certifications
Markyard holds no certification against SOC 2, ISO 27001, HIPAA, PCI or any other formal framework.
Report a security issue
If you find a security problem in Markyard, we want to hear about it before anyone else does. Reach us through the contact page and describe what you found; we will follow up directly.