Security & Confidentiality
Last updated: April 2026
This page explains how Identity Market handles security issue reporting, confidentiality, and controlled access to sensitive business and creator materials.
Table of Contents
1. Security Reporting
If you discover a security issue affecting Identity Market, report it privately before any public disclosure.
Send reports to security@identity-market.com. Include the affected URL or route, reproduction steps, expected impact, and any time-sensitive containment details.
Do not exploit, extort, access other users' data, or publish details before Identity Market has had a reasonable opportunity to investigate and respond.
2. Platform Controls
- Authenticated sessions use server-controlled cookies and sensitive account areas are served with restrictive caching.
- State-changing account actions include request-origin checks and other abuse-reduction controls.
- Public-facing sensitive flows use rate limiting and monitoring to reduce automated abuse.
- Browser responses include standard hardening headers appropriate for a hosted web application.
- Private asset delivery is brokered through controlled, time-limited access rather than permanent public links.
3. Confidentiality Boundaries
Identity Market may share restricted materials with creators, contractors, agencies, technical reviewers, and professional advisers only where needed for a defined business purpose.
- Restricted creator, contractor, and partner materials should only be shared for a defined purpose and only after the correct agreement stack is in place.
- An NDA does not transfer any ownership, licence, partnership right, or announcement right unless a signed follow-on agreement says so explicitly.
- Sensitive materials should not be uploaded into third-party AI tools, shared drives, or public links unless that use is expressly approved in writing.
- Access should be limited to need-to-know recipients and removed immediately when a review, negotiation, or engagement ends.
4. Creator & Partner Access
Before sensitive collaboration begins, the correct document stack should be chosen based on the relationship: NDA, creator agreement, contractor agreement, IP assignment, and scoped access controls where relevant.
For legal enquiries about collaboration boundaries or confidentiality obligations, contact legal@identity-market.com.
5. Collaboration Document Stack
Identity Market uses layered protections rather than relying on one document alone. The required documents depend on the relationship, access level, and work being performed.
- Appropriate confidentiality terms before restricted access, demos, internal materials, or unreleased business information are shared.
- Creator or contractor agreement before any deliverables, revenue share, production work, or ongoing collaboration begins.
- IP assignment or express platform-use rights wherever work product, edits, prompts, automations, or brand assets are being created for Identity Market.
- Written approval before any publicity, logo use, case-study reference, announcement, or external mention of the relationship.