Security
Security and data handling.
What we run, what we store, and what we’ll never do with your data. Short answers, stated plainly, so you can forward this page to whoever signs off.
The practices
How the service is run.
Infrastructure
DeedGraph runs on AWS in us-east-1. Traffic is TLS-encrypted in transit and the database is encrypted at rest. The marketing site you are reading holds no customer data at all.
Payments
Stripe processes every payment. Card numbers never touch our servers; we store only the Stripe customer reference and your subscription state.
What we hold about you
Your account email, your search and dossier history, and whatever you choose to send through a lead form. We don't sell customer data, and we don't share it outside the processors that run the service.
The property data itself
Public records published by NYC and New York State agencies, plus open-web corroboration with citations. No consumer credit data, ever.
Team & Enterprise controls
Shared workspaces with per-user seats are open to every account during the beta. SSO, audit logs and a custom MSA / DPA are the Enterprise controls, and procurement teams that need them now should email us.
Data removal
Named in a public record and want it gone from DeedGraph? File a removal request and a human reviews it. No form-letter loop.
The removal process lives at /legal/removal-request, and the privacy policy covers the formal detail.
Certifications
Where we are, honestly.
We’re a small team and we won’t pretend otherwise: there’s no SOC 2 report today. If your procurement process needs specifics on our current posture, email hello@deedgraph.com and you’ll get straight answers from the founder, usually the same day.
Responsible disclosure
Found a vulnerability?
Email hello@deedgraph.com with enough detail to reproduce it. We read every report, we’ll respond, and we won’t pursue anyone acting in good faith.