Trust & security

How OpenGraph+ handles your data, and why it stays out of your critical path.

OpenGraph+ runs outside your infrastructure, reads only the public pages you point it at, and stores almost nothing. Not much for a security review to snag on.

Security posture
opengraphplus.com
Data residency
United States
Encryption in transit
TLS enforced
Encryption at rest
AES-256-GCM
Passwords stored
None
Page content stored
None
SSRF protection
Enabled
Breach notice
≤ 72 hours
Tenant isolation
Enforced

Why security teams clear us quickly

The four things a reviewer asks first, answered up front.

Outside your perimeter

No agents, SDKs, or scripts run in your environment. The only integration is an API key you generate and can revoke at any time.

Public URLs only

OpenGraph+ fetches only the pages you submit. Private, reserved, and cloud metadata IP ranges are blocked at the network layer, so it cannot reach internal services.

Minimal data footprint

No passwords. No payment data. No page content. We render a screenshot, extract the Open Graph tags, and discard the HTML.

Encrypted and isolated

TLS in transit, encryption at rest, and every query scoped to a single tenant. There is no shared namespace between customers.

Compliance posture

We run OpenGraph+ to the bar a formal audit would set: least-privilege access, encryption in transit and at rest, strict tenant isolation, and breach notice within 72 hours. We're not SOC 2 or ISO 27001 certified yet, but we hold that posture and take it every bit as seriously as a certified vendor would.

OpenGraph+ · operated by Rocketship, LLC

Talk it through with a human

A security review that needs a real answer, a questionnaire to complete, or a control to walk through? Reach a person on our team, not a bot.