Security Policy

Last updated: April 2026

Markable takes the security of your data seriously.

Technical measures:

  • All data is encrypted in transit using TLS
  • All data is encrypted at rest
  • Authentication is handled by Supabase Auth with industry-standard security
  • Passwords are never stored in plain text
  • Access to production systems is restricted to authorised personnel only

Organisational measures:

  • Regular security reviews
  • Staff access to data is on a need-to-know basis
  • Incident response procedures are in place

Reporting a security issue: If you discover a security vulnerability please contact us immediately at support@markable.uk. Do not disclose security issues publicly before we have had the opportunity to address them.

Data breach procedure: In the event of a breach we will notify affected users and the ICO within 72 hours as required by UK GDPR.