What security reviewers need in one place: our certifications, data handling, sub-processors and legal posture for public web data. Items marked for confirmation are being prepared for publication.
We operate to ISO/IEC 27001:2022 information-security practices. TODO(owner): publish the certificate issuer, scope and validity dates, and a link to the certificate.
Our processes align with GDPR principles; we collect only public, non-personal data. TODO(owner): link the Data Processing Agreement (DPA) and name the data-protection contact.
Infrastructure and delivery rely on a small set of vetted providers. TODO(owner): publish the current sub-processor list (name, purpose, region).
Data is encrypted in transit, access is role-restricted, and we retain only what a delivery requires. TODO(owner): confirm encryption-at-rest, retention windows and access-control specifics.
We collect data openly accessible on the public web and never access login-walled, paywalled or authenticated content. See our privacy & data ethics page.
Courts (incl. the 9th Circuit in hiQ v. LinkedIn) have held that accessing publicly available data does not by itself violate the US CFAA — but rules vary by country, data type and site terms. We collect public, non-personal data and review target-site terms. TODO(owner): counsel to approve final wording.
“Compliance is the thing here. We consume competitor rate data and regulatory updates through their API into our Kafka topics, and every record carries a source ID and timestamp. Our internal audit sign-off, which used to take three rounds of back-and-forth, went through in one pass. I've been at the bank 18 years and that's not nothing.”
Banking group