What the platform does.
AES-256 encryption at rest
Sensitive fields — from SSO credentials to multi-factor secrets — are encrypted with AES-256-GCM under a key the config layer requires before the service boots.
TLS-encrypted traffic at the ingress
Traffic to every service — this site, the dashboard and the API — is encrypted in transit and terminated at the Azure ingress in front of it.
Multi-factor sign-in
Sign-in factors are enrolled per user — SMS, voice, WhatsApp, email and authenticator apps (TOTP) — with single-use recovery codes.
Passwordless sign-in options
An emailed one-time link or a mobile one-time code is a complete sign-in on its own, on the channel you choose.
Password policy and hashing
Passwords must meet a complexity policy at every entry point and are stored only as bcrypt hashes.
Brute-force lockout
Five failed sign-ins in fifteen minutes lock the account for fifteen minutes — checked before the password is even compared.
Short-lived sessions
Access tokens expire in minutes, refresh flows re-verify the session, and realtime connections use their own short-lived tokens.
Single sign-on
Sign in with Google or Microsoft on every plan; connect your organization’s own identity provider with Single Sign-On on Automate.
Role-based access with explicit membership
Access to a tenant requires an explicit membership with a tenant-specific role, validated on every request and revoked with the membership.
Tenant isolation on every query
Every query runs scoped to one authorized organization; there is no cross-tenant read path.
Channel-aware firewall
Blocking rules name the channels they close — voice, SMS, email, chat and API — and run before anything is persisted.
Tamper-evident audit log
Privileged writes — role changes, orders, payments, number lifecycle — land in an append-only audit log whose integrity is verifiable.
Signed and notarized desktop builds
Desktop apps ship code-signed on Windows and Developer ID-signed and notarized on macOS, built entirely in CI.
Where it runs.
Market Canopy is hosted and supported by Microsoft Azure. The API and background workers run in Azure Container Apps deployed to the West US region, this site and the app dashboard run on Azure App Service, and desktop downloads are served from Azure Storage.
The compliance offerings customers ask about belong to Azure, our host — they are listed here so you know where your data and servers live. Market Canopy holds no certification of its own today.
- SOC 1, SOC 2 and SOC 3
- ISO/IEC 27001, 27017, 27018 and 27701
- PCI DSS
- HIPAA and HITRUST
- FedRAMP High
- CSA STAR
The current list and each offering’s scope live at the Microsoft Trust Center.
