The short version
- Two-step verification with an authenticator app is available on every plan, Analyst included. With it on, signing in, opening billing and changing your desk’s seats all ask for the app’s code.
- We never see or store a card number: Stripe takes payment on its own pages.
- The Market Terminal connects to no broker, custodian or bank, and asks for no client names, account numbers or tax IDs.
- Everything travels over HTTPS. Each account reads only its own records, and a Desk plan team only its team’s.
- We hold no SOC 2 or ISO 27001 report, and single sign-on is not built. We say so here rather than imply otherwise.
- Found a problem? Email hello@themarketterminal.com with “Security” in the subject.
Signing in
Accounts sign in with an email address and a password through Supabase Auth, which stores the password only as a hash, so nobody can read it, us included. An account signs in for the first time only after its email address is confirmed from the link we send. Resetting a password also goes through a link sent to that address.
Signing out removes what you saved in the terminal (watchlist, alerts, portfolios, baskets, chart drawings and layouts) from the browser, so the next person on a shared computer starts empty. It stays in your account for the next time you sign in.
Two-step verification
Turn it on from your Account page, under Sign-in security, with any authenticator app that shows 6-digit codes (for example 1Password, Google Authenticator or Microsoft Authenticator). Scan the QR code or type the key, then enter the first code the app shows. With it on:
- signing in asks for the code after your password, and the terminal does not sign you in until the code is entered;
- opening billing (Stripe’s billing portal, where the plan, the seats and the card change) asks for it;
- inviting someone to your desk, cancelling an invitation and removing a member ask for it. Our servers check this, not only the page.
If you lose the device with the app, email hello@themarketterminal.com from your account’s address. We check that the request comes from you before removing the app from the account; you can then sign in with your password and set up a new one. There are no backup codes yet.
What we store, and what we never hold
We store what the service needs: your email address and name if you give one; your plan and, if you subscribe, your Stripe customer and subscription IDs and the date your paid period ends; and what you save in the terminal (watchlist, price alerts, portfolios and transactions with any notes, baskets, display settings, chart drawings and layouts). On a Desk plan team we also keep the team’s name, its members and their roles, pending invitations and the team’s shared watchlists. The Privacy Policy lists all of it, with how long each is kept.
We never hold:
- card numbers or bank details (Stripe holds those);
- a connection to any broker, custodian, bank or portfolio system: positions in the Portfolio Tracker are only what you type in;
- client names, account numbers, tax IDs or other identifiers of the people you invest for, unless you type them into a note yourself. We ask you not to: a ticker and a quantity are all the tracker needs.
Our page analytics store no IP address, and send nothing at all when your browser sends Global Privacy Control or Do Not Track.
Payments
Checkout, invoices and the billing portal are Stripe’s own pages. Stripe collects and keeps your card and billing details; we receive only your Stripe customer and subscription IDs and the state of your subscription. Stripe signs every event it sends us about a subscription, and our server refuses any event whose signature does not check out.
Who runs the service with us
These companies process account data so that the service works. The Privacy Policy lists every provider, including the ones that only cache market data or serve fonts.
- Supabase
- Our database and sign-in. Stores your account, profile, saved data and Desk plan team data, and sends account email (address confirmation and password reset).
- Vercel
- Hosts the website and our API.
- Stripe
- Payments: checkout, subscriptions, invoices and the billing portal.
- SendGrid (Twilio)
- Delivers our email: the Market Intelligence Bulletin, 13F filing alerts, subscription confirmations, Desk plan invitations and trial reminders.
Encryption and the browser
The website, our API, Supabase and Stripe are reached only over HTTPS, and the site tells browsers to use nothing else (HTTP Strict Transport Security, for two years). Supabase states that it encrypts stored data at rest (supabase.com/security).
Every page carries a Content Security Policy that limits where scripts, styles and data may come from, and refuses to be framed by another site; links to other sites pass on our domain, not the page you were on. The third-party libraries the pages run are copies we host ourselves, checked byte for byte against their published releases; the one loaded from another site, the charting library on the Hyperliquid Funding page, is pinned with Subresource Integrity, so a changed copy does not run.
Who can see what
- In the database, row-level security limits each account to its own records, and a Desk plan team to its team’s. Within a team, viewers read the shared lists and editors change them.
- The keys that bypass those rules are kept on our servers and are never sent to a browser.
- Desk plan invitation links work once, expire after 14 days, and are stored only as a hash, so a copy of our database would not contain a working link.
- The links in our emails that confirm or cancel a subscription are signed, so each works only for the address it was sent to.
- We do not sell your information or share it for advertising.
What we do not have yet
- No SOC 2 or ISO 27001 report, and no independent penetration test to share.
- No single sign-on (SAML or OIDC): accounts sign in with email and password, with two-step verification if you turn it on. Single sign-on is on the Desk plan roadmap and is not part of what you buy today.
- No backup codes for two-step verification, and no audit log of who changed what on a desk.
If your firm sends a security questionnaire, write to hello@themarketterminal.com and we will answer it with what is true today.
Reporting a vulnerability
Email hello@themarketterminal.com with “Security” in the subject. Tell us what you found, how to reproduce it, and what it exposes. Please test only against your own account, do not read or change anyone else’s data, do not degrade the service for others, and give us a reasonable chance to fix the problem before you publish it. We do not run a paid bug bounty.
The same contact is published for automated tools at /.well-known/security.txt.