How We Protect Your Data
Your data security is our top priority. We maintain strict security controls, documented privacy compliance, and transparent practices to protect your information.
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
30 days
Automatic data deletion
24/7
SIEM monitoring
Compliance & Data Protection
How we meet privacy and payment security requirements. Self-assessed unless stated otherwise.
GDPR
EU General Data Protection Regulation. We support data subject rights and use Standard Contractual Clauses for transfers.
CCPA
California Consumer Privacy Act, as amended by the CPRA. Includes an opt-out of sharing for advertising.
PCI DSS
Card payments are handled by Stripe, a PCI DSS Level 1 certified provider. We do not store full card numbers.
Internal Security Policies
Documented access control, encryption, and incident response policies, reviewed at least annually.
Security Controls
Security controls at every layer
Data Encryption
- At Rest
- AES-256 encryption
- In Transit
- TLS 1.3
- Key Management
- AWS KMS with automatic rotation
- Database Encryption
- Transparent Data Encryption (TDE)
Access Control
- Authentication
- Multi-factor authentication (MFA)
- Authorization
- Role-based access control (RBAC)
- API Security
- Bearer token authentication
- Session Management
- Secure JWT with refresh tokens
Infrastructure Security
- Cloud Provider
- AWS with VPC isolation
- Network Security
- Web Application Firewall (WAF)
- DDoS Protection
- CloudFlare Enterprise
- Vulnerability Scanning
- Automated daily scans
Monitoring & Compliance
- Security Monitoring
- 24/7 SIEM with alerts
- Audit Logging
- Immutable audit trail
- Incident Response
- Automated response playbooks
- Control Review
- Internal review, at least annually
Infrastructure Security
Built on AWS infrastructure with multiple layers of protection
Cloud Security
- AWS VPC with private subnets
- Network access control lists
- Security groups and firewalls
- Regular security assessments
Application Security
- Web Application Firewall (WAF)
- API rate limiting and throttling
- Input validation and sanitization
- OWASP Top 10 protection
Performance Security
- DDoS protection via CloudFlare
- CDN with edge security
- Load balancing with health checks
- Auto-scaling security groups
Privacy by Design
Privacy and data protection built into every aspect of our platform
The Data Lifecycle
What happens to a lookup, from first byte to deletion
Day 0
Received
Encrypted in transit with TLS 1.3
Day 0
Validated
Minimal data collection in validation responses
Days 0-30
Stored
AES-256 at rest. No personal data stored beyond validation requirements
Day 30
Deleted
Automatic data deletion after 30 days
Day 0
Received
Encrypted in transit with TLS 1.3
Day 0
Validated
Minimal data collection in validation responses
Days 0-30
Stored
AES-256 at rest. No personal data stored beyond validation requirements
Day 30
Deleted
Automatic data deletion after 30 days
Data Minimization
We only collect and process data necessary for our services
- No personal data stored beyond validation requirements
- Automatic data deletion after 30 days
- Minimal data collection in validation responses
Purpose Limitation
Data is used only for the specific purpose you intended
- Validation data not used for marketing
- No data sharing with third parties
- Clear consent for all data processing
Transparency
Complete visibility into how your data is handled
- Real-time processing logs
- Data processing audit trail
- Clear data retention policies
User Control
You maintain full control over your data
- Download all your data
- Delete data at any time
- Granular privacy controls
Incident Response
We maintain a documented incident response plan with 24/7 monitoring and automated response capabilities to quickly address any security issues.
Detection
< 5 minutes
Assessment
< 15 minutes
Containment
< 30 minutes
Resolution
< 2 hours
Security Questions?
Our security team is available to answer questions about our practices, controls, and compliance requirements.