Demonstration environment. This catalogue contains sample data. Products, vendors and availability shown are illustrative and are not offered for sale.

Market Express
ProductsTAA ComplianceSection 889ContractsProcurementBecome a VendorSupport

Security

Market Express Government is built to support federal, state, and local agency procurement with data handling controls aligned to government security requirements. This page covers our practices, FISMA considerations, and responsible disclosure.

Agency Data Isolation

Government channel accounts are logically separated from commercial channels. Order records include contract vehicle, CAGE code, and agency identifiers for audit.

CUI Handling Policy

No Controlled Unclassified Information (CUI) may be transmitted through the platform. Do not include classified information in order notes or support tickets.

Compliance Posture

FedRAMP authorization is on our roadmap. Current compliance documentation (SOC 2, PCI-DSS, ITAR attestation) is available on request from your contracting officer.

Payment Security

PCI-DSS Level 1

Our payment processors are PCI-DSS Level 1 certified. Market Express never stores raw card numbers.

3D Secure 2.0

Supported on all card transactions. Provides an additional layer of authentication for high-risk purchases.

Tokenization

Payment methods are stored as secure tokens with our payment processors — never on Market Express servers.

Fraud Detection

Transactions are screened for fraud by our payment processor. Unusual activity triggers manual review before fulfillment.

Government Data Handling

Market Express Government is designed to support federal, state, and local agency procurement requirements.

  • Agency account data is logically isolated from commercial channels (B2B, B2C)
  • Order records include contract vehicle, CAGE code, and agency identifiers for audit purposes
  • No CUI (Controlled Unclassified Information) may be transmitted through the platform
  • FedRAMP authorization is on our roadmap — contact us for current compliance documentation
  • ITAR-controlled items are not listed on the Government channel
  • SAM.gov / UEI integration for vendor verification is supported

For FISMA, ATO, or data handling questionnaires, email security@marketexpres.us with subject line Government Compliance Request.

Agency Account Security

  • Assign accounts only to authorized procurement and contracting staff
  • Contracting officers should use agency email addresses, not personal accounts
  • Review team member access quarterly and remove separated employees promptly
  • Do not enter agency network credentials or CAC PINs on the platform
  • Report suspected unauthorized access to your IT security officer and security@marketexpres.us

Responsible Disclosure

We welcome reports from security researchers who discover vulnerabilities in our platform. Please follow these guidelines to ensure a coordinated and responsible disclosure process.

In Scope

  • marketexpress.us and all subdomains (www, business, buyersclub, government, dobusiness, marketing, vendors, admin, api, auth, status)
  • Market Express iOS and Android mobile applications
  • Market Express APIs (authenticated and unauthenticated endpoints)
  • Authentication and authorization systems
  • Payment processing and checkout flows
  • Vendor portal and admin panel

Out of Scope

  • Third-party services (Stripe, PayPal, FedEx, USPS, FusionAuth)
  • Social engineering or phishing attacks against Market Express staff
  • Denial of service (DoS/DDoS) attacks
  • Automated scanning without prior written approval
  • Physical security of data centers or offices
  • Issues already reported by another researcher

Safe Harbor

If you make a good-faith effort to comply with this policy during your security research, we commit to the following:

  • We will not pursue civil or criminal action against researchers who follow these guidelines
  • We will acknowledge receipt within 2 business days
  • We will keep you informed of our progress toward resolution
  • We will credit you in our acknowledgements (unless you prefer anonymity)

Report a Vulnerability

Email our security team with a description of the issue, steps to reproduce, and potential impact. For government data handling inquiries include your agency and contracting officer contact.

security@marketexpres.us

PGP key available on request

Response within 2 business days · Mon–Fri 8am–6pm PT

What to Include in Your Report

  • Description of the vulnerability and its potential impact
  • URL, endpoint, or component affected
  • Step-by-step instructions to reproduce
  • Screenshots, logs, or proof-of-concept (no live exploit code)
  • Your name / handle for acknowledgement (optional)