Security & compliance

What security reviewers need in one place: our certifications, data handling, sub-processors and legal posture for public web data. Items marked for confirmation are being prepared for publication.

ISO/IEC 27001:2022

We operate to ISO/IEC 27001:2022 information-security practices. TODO(owner): publish the certificate issuer, scope and validity dates, and a link to the certificate.

GDPR & DPA

Our processes align with GDPR principles; we collect only public, non-personal data. TODO(owner): link the Data Processing Agreement (DPA) and name the data-protection contact.

Sub-processors

Infrastructure and delivery rely on a small set of vetted providers. TODO(owner): publish the current sub-processor list (name, purpose, region).

Data handling

Data is encrypted in transit, access is role-restricted, and we retain only what a delivery requires. TODO(owner): confirm encryption-at-rest, retention windows and access-control specifics.

Public data only

We collect data openly accessible on the public web and never access login-walled, paywalled or authenticated content. See our privacy & data ethics page.

Legal posture

Courts (incl. the 9th Circuit in hiQ v. LinkedIn) have held that accessing publicly available data does not by itself violate the US CFAA — but rules vary by country, data type and site terms. We collect public, non-personal data and review target-site terms. TODO(owner): counsel to approve final wording.

Get a free sampleBook a call

Trusted on compliance

“Compliance is the thing here. We consume competitor rate data and regulatory updates through their API into our Kafka topics, and every record carries a source ID and timestamp. Our internal audit sign-off, which used to take three rounds of back-and-forth, went through in one pass. I've been at the bank 18 years and that's not nothing.”

Banking group

close