Approved-member access with a branded authentication boundary.
MarketKeel currently uses invite-only access, secure email links and Google authentication. The application derives organization membership and role scope on the server instead of trusting a browser-supplied organization identifier.
Organization isolation is enforced in the application and database.
Workspace reads and writes are scoped to authenticated membership, with row-level policies and negative tenant tests. Invitations, revocations and cross-organization denial are treated as audited workflows rather than interface-only permissions.
Credentials stay outside source control and customer artifacts.
MarketKeel-specific provider and deployment credentials are kept in the MarketKeel LLC secrets boundary. Repository checks reject credential material, runtime names are scoped to MarketKeel, and customer-visible errors omit raw provider diagnostics.
Evidence context is minimized, traced and redacted.
Model requests receive only the evidence and workspace context required for the task. Stored evidence passes through centralized redaction, and saved briefs retain source and version context. Do not submit material nonpublic information, regulated personal data, or third-party confidential information unless your organization is authorized and MarketKeel has approved the use case.
Availability is measured separately from security and evidence quality.
Health checks, authentication boundaries, backup restoration and production smoke tests are part of release review. Connector failures must remain visible, and stale or last-good evidence must not be presented as a successful current refresh.
The controlled beta is not a certification claim.
MarketKeel does not currently claim SOC 2, ISO 27001, HIPAA, PCI merchant storage, or universal enterprise readiness. Card details are handled by Stripe-hosted payment pages. Prospective customers should discuss data classification, procurement, retention, export and deletion requirements before placing sensitive research in the service.