Skip to content

Security

Security at Deindex

Deindex encrypts your data in transit and at rest, restricts access on a least-privilege basis, deletes your personal data within 30 days of cancellation, names every sub-processor it uses, and offers a DPA to Business customers. SOC 2 is in progress, not yet certified, and we say so plainly.

Last updated July 13, 2026

At a glance

  • Data is encrypted in transit (TLS) and at rest.
  • Access to personal data is restricted to the staff and systems that need it, on a least-privilege basis.
  • Cancel your account and we delete your personal data within 30 days, except records we must keep by law.
  • Five named sub-processors, no more, listed in a real table below.
  • SOC 2 is in progress, not certified. We say so rather than imply otherwise.

How we handle data

Encryption

All traffic to and from Deindex is encrypted in transit over TLS. Personal data at rest, including scan results, removal records and evidence screenshots, is stored encrypted in our primary database and file storage. Passwords are never stored in plain text; we keep a one-way salted hash only.

Least-privilege access

Only the staff and automated systems that need a piece of data to do their job can reach it. Administrative access to production data is limited, individually accountable, and logged. There is no shared or generic admin login.

Retention and deletion on cancel

We keep your account and removal data for as long as your account is active, because monitoring for relisting is ongoing work. When you cancel, we delete your personal data within 30 days, except records we are legally required to keep, such as billing records for tax purposes, which we retain only for the required period. Anonymous scan data that is no longer linked to a person is deleted or aggregated. Full detail is in our Privacy Policy.

Infrastructure

The application runs on a small set of vetted providers rather than a sprawling stack. Scanning and evidence capture run on self-hosted headless Chrome infrastructure we operate ourselves, so the record of what a broker page looked like on a given day is captured directly, not sourced from a third-party scraping API we do not control. The primary data store is MySQL, encrypted at rest. Backups are encrypted and access-controlled the same way production data is.

Sub-processors

We keep this list short on purpose. Every company below acts on our instructions only, under a data processing agreement where personal data is involved.

Deindex sub-processors and what each one processes
Sub-processor Role What they process
Stripe Payment processing Card details and billing status for paid subscriptions. We never see or store your full card number.
Amazon SES Transactional email Verification codes, exposure reports, removal-status updates, and the erasure requests we send to brokers on your behalf.
Self-hosted headless Chrome Scanning and evidence capture Runs the exposure scan against broker and people-search sites and captures the dated before/after evidence screenshots. Runs on our own infrastructure, not a third-party scraping API.
bunny.net Web font delivery Serves our typefaces from a privacy-respecting mirror. No visitor logging or tracking cookie, unlike Google Fonts.
MySQL Primary data store Holds account, profile, scan, removal and evidence records, encrypted at rest.

An up-to-date copy of this list is available on request to [email protected].

DPA availability

A Data Processing Agreement, naming every sub-processor above and setting out our obligations as processor and yours as controller, is available for Business and Executive customers on request. If your procurement process requires a signed DPA before a purchase order, email [email protected] and we will send it. See Deindex for Business for invoicing, SSO and SLA detail.

SOC 2 and compliance roadmap

We are not SOC 2 certified today. A SOC 2 Type II report is on our roadmap and work is in progress: access controls, change management and incident response are already run the way an audit expects, and formal certification is the next step, not a claim we make early. We would rather tell a security reviewer honestly where we stand than print a badge we have not earned.

No Google Fonts

Every typeface on this site is self-hosted and served from bunny.net, a privacy-respecting font mirror that does not log or track visitors. On a privacy product, quietly shipping Google's font tracker on every page would be a small lie inside a large promise, so we do not.

Responsible disclosure

If you find a security issue in Deindex, tell us before you tell anyone else. Email [email protected] with enough detail to reproduce the issue. We will acknowledge your report, investigate, and keep you updated as we fix it. Please give us a reasonable window to resolve an issue before any public disclosure, and avoid accessing or modifying data that is not yours while testing.

Security contact

For any security question, a DPA request, or a vulnerability report, email [email protected]. This is the only address to use to reach us. See also our Privacy Policy for how we handle personal data end to end, and what we cannot remove for the honest scope of the service.

Get started