MarkerKit is built for teams that care about data protection, reliability, and transparency.
This page outlines how we secure the platform across infrastructure, app code, and operations.
Last updated: 2025-10-29
Architecture
Providers / Locations
Secrets & Config
Authentication & Sessions
Secure, and SameSite cookies.Data Isolation
APIs
Dependencies & Builds
Data Minimalism
Processing & Storage
Retention & Deletion
Cookies
We use the following service providers to deliver MarkerKit:
| Provider | Purpose | Region / Notes |
|---|---|---|
| Cloudflare | DNS, CDN, DDoS, WAF, TLS | Global edge |
| Hetzner | App compute | EU (Germany) |
| Google Firebase | Auth, Firestore, RTDB | EU multi-region (where available) |
| AWS (S3, SES, SSM/KMS) | Storage, email, secrets | eu-central-1 |
| Stripe | Payments | Global (PCI DSS L1) |
| QuestDB | Analytics events | Private EU environment |
(We will notify customers of material sub-processor changes.)
If you believe you’ve found a vulnerability, email security@markerkit.com with details.
We aim to acknowledge within 48 hours and will coordinate remediation and disclosure.
MarkerKit VCC
UIC 208561215
Registered in Sofia, Bulgaria