This page is written for the security and procurement teams evaluating American Trades Index. It describes where our data comes from, what we store, how we protect it, how long we keep it, and the third parties that help us run the Service. If you need a security questionnaire completed or a more detailed conversation under NDA, contact us at the address below.
American Trades Index is built entirely on public data. We do not buy data from brokers, and we do not scrape private or password-protected accounts.
Every figure traces to a source of record. We do not create facts about a licensee; the government register that issued the license is the authority. Where a register corrects its data, we reflect the corrected data on our next refresh.
The licensing corpus. The public-record fields described above, plus the historical changes to those records that power the movement history at the core of the Service. We deliberately do not collect or publish Social Security numbers, dates of birth, driver's-license numbers, or photographs.
Customer account data. Your email address and, if you provide them, your name and company; your usage of the Service (API requests and features used) in a self-hosted event log we do not sell or share for advertising; and, on paid plans, billing details handled by our payment processor. We never store full payment-card numbers. API keys are stored only as hashes, never in plaintext.
What we do not do. We do not sell customer account data. We do not use your in-product assistant prompts to train models (see Subprocessors).
No method of transmission or storage is perfectly secure, and we describe our practices honestly rather than promising perfection.
We use a small set of reputable service providers to run the Service. Each operates under its own security program and processes only the data needed for its function.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | DNS, CDN, and website delivery | Website request metadata |
| Fly.io | Application and API hosting | API and product requests |
| Supabase | Authentication and primary database | Account data and the data corpus |
| Stripe | Payment processing and billing | Billing details (Stripe stores card data; we do not) |
| Resend | Transactional and newsletter email | Email address and message content |
| OpenRouter and its model providers | In-product AI assistant inference | Assistant prompts, under zero-retention terms |
Prompts sent to the in-product assistant are processed under zero-data-retention terms: they are not retained by the model provider and are not used to train models. We will post material changes to this list here.
We are candid about where we are. American Trades Index is an early-stage company and does not yet hold a SOC 2 or ISO 27001 certification. What we can offer today: the practices described on this page, completion of your standard security questionnaire, and a more detailed technical conversation under NDA. Because the data we publish is drawn from public government registers rather than private personal data, the risk profile of the underlying dataset is different from a typical personal-data vendor.
If you believe you have found a security vulnerability, please email [email protected] with the details and steps to reproduce. We will acknowledge your report, keep you updated, and will not pursue or support legal action against good-faith security research. Please give us a reasonable window to remediate before any public disclosure.
Our Privacy Policy covers how we handle customer and licensee information, and our Terms of Service cover acceptable and permitted use of the data. For security, privacy, or procurement questions, or to request a completed questionnaire, contact [email protected].