Trust and Security

Last updated 2026-08-25

This page is written for the security and procurement teams evaluating American Trades Index. It describes where our data comes from, what we store, how we protect it, how long we keep it, and the third parties that help us run the Service. If you need a security questionnaire completed or a more detailed conversation under NDA, contact us at the address below.

1. Where our data comes from

American Trades Index is built entirely on public data. We do not buy data from brokers, and we do not scrape private or password-protected accounts.

Every figure traces to a source of record. We do not create facts about a licensee; the government register that issued the license is the authority. Where a register corrects its data, we reflect the corrected data on our next refresh.

2. What we store

The licensing corpus. The public-record fields described above, plus the historical changes to those records that power the movement history at the core of the Service. We deliberately do not collect or publish Social Security numbers, dates of birth, driver's-license numbers, or photographs.

Customer account data. Your email address and, if you provide them, your name and company; your usage of the Service (API requests and features used) in a self-hosted event log we do not sell or share for advertising; and, on paid plans, billing details handled by our payment processor. We never store full payment-card numbers. API keys are stored only as hashes, never in plaintext.

What we do not do. We do not sell customer account data. We do not use your in-product assistant prompts to train models (see Subprocessors).

3. Security practices

No method of transmission or storage is perfectly secure, and we describe our practices honestly rather than promising perfection.

4. Data retention

5. Subprocessors

We use a small set of reputable service providers to run the Service. Each operates under its own security program and processes only the data needed for its function.

ProviderPurposeData involved
CloudflareDNS, CDN, and website deliveryWebsite request metadata
Fly.ioApplication and API hostingAPI and product requests
SupabaseAuthentication and primary databaseAccount data and the data corpus
StripePayment processing and billingBilling details (Stripe stores card data; we do not)
ResendTransactional and newsletter emailEmail address and message content
OpenRouter and its model providersIn-product AI assistant inferenceAssistant prompts, under zero-retention terms

Prompts sent to the in-product assistant are processed under zero-data-retention terms: they are not retained by the model provider and are not used to train models. We will post material changes to this list here.

6. Compliance posture

We are candid about where we are. American Trades Index is an early-stage company and does not yet hold a SOC 2 or ISO 27001 certification. What we can offer today: the practices described on this page, completion of your standard security questionnaire, and a more detailed technical conversation under NDA. Because the data we publish is drawn from public government registers rather than private personal data, the risk profile of the underlying dataset is different from a typical personal-data vendor.

7. Reporting a vulnerability

If you believe you have found a security vulnerability, please email [email protected] with the details and steps to reproduce. We will acknowledge your report, keep you updated, and will not pursue or support legal action against good-faith security research. Please give us a reasonable window to remediate before any public disclosure.

8. Policies and contact

Our Privacy Policy covers how we handle customer and licensee information, and our Terms of Service cover acceptable and permitted use of the data. For security, privacy, or procurement questions, or to request a completed questionnaire, contact [email protected].