Off-Nadir Delta
← Back to Home

Trust & Security

Off-Nadir Delta is built to be used in production and evaluated by security teams. This page summarizes how we protect your data, who our subprocessors are, where we stand on compliance, and how to report a vulnerability. For a Data Processing Agreement (DPA), a subprocessor list, or to run a security review, email support@offnadir-lab.com.

How is my data protected?

  • Encryption in transit — all traffic is served over HTTPS/TLS; plain-HTTP requests are upgraded.
  • API keys — stored only as SHA-256 hashes, never in plaintext. The secret is shown once at creation and can be revoked at any time from your account.
  • OAuth tokens — access tokens are short-lived; refresh tokens are stored hashed and rotated, with reuse detection.
  • Access control — data is protected with database row-level security (RLS); sensitive tables (keys, tokens) are reachable only by trusted server roles.
  • Authentication — handled by a managed identity provider; we never store your password.
  • Payments — processed by Stripe (PCI DSS Level 1). We do not see or store card numbers.
  • Abuse protection — rate limiting is applied to public and authenticated endpoints.

What data do you handle?

Event intelligence is derived from open-source news media — there is no covert or private-source collection. Account data is minimal (your email and usage), and usage is metered on a token balance. You can delete your account and associated data at any time from your account settings.

Who are your subprocessors?

We rely on a small number of reputable providers to run the service:

  • Payments — Stripe (PCI DSS Level 1).
  • Cloud infrastructure & database — reputable US-based cloud providers.
  • Transactional email — a third-party email delivery provider.

A detailed, named subprocessor list is available to customers on request (under NDA).

What about compliance (SOC 2, GDPR, DPA)?

Off-Nadir Delta is an independent product. We are not yet SOC 2 certified, but we are glad to complete your security questionnaire and can provide a Data Processing Agreement (DPA) on request. We support data access and deletion consistent with GDPR principles. For a DPA, the named subprocessor list, or a security review, contact support@offnadir-lab.com.

How do I report a vulnerability?

We welcome good-faith security research. Report any vulnerability to support@offnadir-lab.com. We will not pursue legal action for research that respects user privacy, avoids service disruption and data destruction, and gives us reasonable time to remediate before any public disclosure. Machine-readable details are published at /.well-known/security.txt.

Enterprise & teams

Running Off-Nadir Delta in production or rolling it out to a team? We can discuss committed / annual volume, invoicing and purchase orders, a DPA, and SLA & priority support. Contact us or see pricing.

See also our Methodology & AI Limitations, the system status, the API & MCP changelog, and our Terms of Service. This page describes current practices and is provided for transparency; it is not a contractual commitment. Specific contractual terms (DPA, SLA) are agreed per engagement.