Security Policy
Last updated: July 22, 2025
Marketscience delivers modeling and simulation tools and related advisory services to clients that inform the measurement and optimization of their business and marketing investments. Security and Compliance is a critical part of Marketscience’s ability to work effectively and safely with our clients.Â
Â
Information SecurityÂ
Marketscience encrypts and protects sensitive information across the transformation and analysis process.Â
- Data in Transit- TLS encryption for all data exchanged. Additional security is available for dedicated VPN connections between Marketscience and our Customers and SuppliersÂ
- Data at Rest – AES 256-bit encryptionÂ
- Network Security – Intrusion detection systems and alerts to monitor for real-time threats, including the use of USM Anywhere and AlienVaultÂ
Access Management & AuthenticationÂ
Marketscience’s platform provides full control of access to all hosted informationÂ
- Account Authentication: Is managed with Microsoft Entra and Azure Active DirectoryÂ
- Password Policies: Required strength factors (minimum characters, required numbers and special characters, common passwords rejected), salted and hashed password storage, and password resetsÂ
- Granular Access Control and Review: Role-based access, visibility and user access rights. Regular access review and analysisÂ
- Audit and Access Logging: Detailed tracking and audit logging of all activities related to the application environment and administrative activity.Â
Software Development PracticesÂ
Security processes and have been fully integrated into the Marketscience software development processes. Developers receive training that focuses on OWASP specific guidelines. In addition, processes are setup to allow for separation of duties and segmentation of platforms with dev, staging, and production.Â
- OWASP based security controls designÂ
- Separation between dev, staging, and prodÂ
- Use of test data in development environmentÂ
- Code peer reviewÂ
- Penetration testingÂ
- Code repository controlsÂ
- Threat modelingÂ
- Deployment controlsÂ
Infrastructure SecurityÂ
Marketscience leverages Amazon Web Services (AWS) and Microsoft Azure. We utilize hardening practices from the Center for Internet Security (CIS) Benchmarks for the platform configuration. Marketscience can make available all standards, AWS and Azure certifications and accreditations along with physical security controls.Â
Company Policies and ProceduresÂ
Marketscience security, risk, and compliance processes were developed based on industry best practices and are reviewed and updated on an annual basis or upon any significant change.Â
- Security Policies and Training – All employees go through required training upon hire and must recertify on an annual basis. Policies include:Â
- Access ControlÂ
- Business ContinuityÂ
- Disaster RecoveryÂ
- Cryptographic ControlsÂ
- Data ManagementÂ
- Human Resources SecurityÂ
- Information SecurityÂ
- Operations SecurityÂ
- Physical SecurityÂ
- Risk ManagementÂ
- Third Party Risk ManagementÂ
- Platform Security – On-going security activities, including:Â
- Network intrusion detectionÂ
- Code vulnerability scanningÂ
- Penetration testingÂ
- System, network, application log analysis, reporting, and retentionÂ
- Incident Response Planning & Team in place to handle any significant security event to triage and respond to establish system resiliency, minimize impact, and protect customer data.Â
Â
Regular Third-Party Security Review that identifies and evaluates security risks of vendors and third parties.Â
Â
Standards and CertificationÂ
Marketscience is committed to establishing and maintaining compliance with key information security and regulatory standards, including:Â
- Service Organization Control (SOC) 2Â
- HIPAAÂ
- CSA Controls MatrixÂ
Marketscience and third-party certification and verification reports are available for limited distribution and shared under non-disclosure agreements.Â
Â
Helpful LinksÂ
CSA Security Standards - https://cloudsecurityalliance.org/star/Â
AWS Risk and Compliance - https://aws.amazon.com/compliance/programs/Â
Marketscience Privacy Policy - https://market.science/privacy-policy/Â
