Trust
Security at MarkKings Group
Last reviewed January 1, 2026
Security is foundational to how MarkKings Group LLC designs, builds, and operates its websites and services. This page describes the controls and practices we use to protect data and how to responsibly report a vulnerability. It is maintained by MarkKings Group LLC and is not a certification.
Program
Controls and Practices
Encryption
Data is encrypted in transit using TLS. Sensitive data at rest is encrypted with modern, industry standard algorithms managed by our hosting providers.
Access Control
Role based access, least privilege, and multi factor authentication are enforced for team members and administrative systems.
Secure Infrastructure
Applications run on reputable cloud providers with hardened baselines, isolated environments, and automated patching for supported components.
Monitoring and Logging
Application, database, and access logs are collected and monitored for anomalies. Alerts route to on call engineers for triage.
People and Training
Team members are vetted, sign confidentiality agreements, and receive security awareness training aligned to their role.
Application Security
We follow secure development practices, including code review, dependency scanning, and periodic security assessments of production workloads.
Shared Responsibility
Security is a shared responsibility. MarkKings Group LLC operates and secures the platforms we provide. Clients and users are responsible for safeguarding their account credentials, configuring the features they enable, and using the services in a lawful and appropriate manner.
Data Handling
We collect only the information needed to deliver our services and support clients. Access to personal data is limited to authorized personnel with a legitimate business need. Retention periods align with our Privacy Policy and applicable legal obligations.
Third Party Providers
We rely on established service providers for hosting, communications, and analytics. Each provider is selected based on its security posture, and the relationship is governed by a written agreement that addresses confidentiality and data protection.
Incident Response
We maintain an incident response process to identify, contain, investigate, and remediate security events. If an incident affects your data, we will notify affected parties consistent with contractual and legal requirements.
Business Continuity
Backups and recovery procedures are in place for the systems that host our websites and client engagements. Runbooks and on call rotations support timely response to outages.
Report
Responsible Disclosure
If you believe you have found a security vulnerability in a MarkKings Group LLC website or service, we appreciate a coordinated disclosure. Please email details to our security contact and give us a reasonable window to investigate and remediate before any public disclosure.
Please include a clear description, steps to reproduce, affected URLs or endpoints, and any supporting evidence.
Please do not access data that does not belong to you, disrupt services, or run automated scans that could impact availability. Acting in good faith and within these guidelines will not lead to legal action from MarkKings Group LLC.
