Security & data handling
What we hold, where it goes, how it's kept
Sourcemark checks whether a business is who it says it is. Most of the data we work with is already public, and we keep as little of yours as the job needs. This page lays out exactly what that means. If a buyer's security team has a question we don't answer here, write to us and a person will reply.
Last reviewed 17 July 2026.
What we collect
- To run your account: your email address and a password. The password is hashed before it's stored, so no one at Sourcemark can read it.
- When you run a scan: the URL or business name you submit, and the verdict we produce from it.
- Owners you choose to screen: if you enter a person's name to check against sanctions and PEP lists, we save it with that scan so you can re-run the check later. You can delete it whenever you want.
What we don't collect
A verdict is built from records about the business: sanctions and PEP lists, company registries, domain registration, archived pages, and threat feeds. We don't ask for or store your customers' personal information, card numbers, or bank details. If your compliance workflow needs to attach that kind of data, it stays in your systems, not ours.
Where your data lives
We run on a small set of established providers rather than reinventing infrastructure. Each one handles a specific job:
| Provider | What it does |
|---|---|
| Render | Runs the application (US region) |
| Supabase | Hosts the database |
| Stripe | Processes payments |
| Resend | Sends account email (verification, password resets) |
How it's protected
- In transit: every connection to Sourcemark uses HTTPS.
- At rest: the database and its backups are encrypted by our hosting providers.
- Passwords: stored as a one-way hash, never in readable form.
- Payments: your card goes straight to Stripe's checkout. It never touches our servers, and we never see the number.
- The scanner: before it fetches a URL you give it, it checks where that URL resolves and refuses to reach internal or private addresses. A link you submit can't be turned into a way into systems it shouldn't touch.
On certifications
We'll be straight with you: Sourcemark is not SOC 2 certified. We're early, and a real audit costs money and months that we're putting toward the product first. We'd rather tell you that than imply otherwise.
Here's what we can give you that a badge can't. Every signal in a Sourcemark verdict links back to the record it came from, whether that's an OFAC entry, a Companies House filing, or an archived page. You don't have to trust our score. You can open the source and check it yourself. That is the whole idea of the product, and it's the reason a verdict holds up when someone asks how you reached it.
Your data stays yours
- Export: download any scan as a PDF or CSV from your dashboard.
- Deletion: ask us to remove a scan or close your account and we'll do it.
- No resale: we don't sell your information or share it for advertising. Running a scan means looking the subject business up in public registries and sanctions lists, but that's the company's own public data, not yours.
Reporting a security issue
If you find a vulnerability, email support@madodigital.net. Tell us what you found and how to reproduce it. We read every one and we won't come after anyone who reports in good faith.
Evaluating Sourcemark and need a data processing agreement or a security questionnaire filled out? Email support@madodigital.net and we'll work through it with you.