Trust & security

How OpenGraph+ handles your data, and why it stays out of your critical path.

OpenGraph+ runs outside your infrastructure, reads only the public pages you point it at, and stores almost nothing. Not much for a security review to snag on.

Security posture
opengraphplus.com
Data residency
United States
Encryption in transit
TLS enforced
Encryption at rest
AES-256-GCM
Passwords stored
None
Page content stored
None
SSRF protection
Enabled
Breach notice
≤ 72 hours
Tenant isolation
Enforced

Why security teams clear us quickly

What a reviewer asks first, answered up front.

Outside your perimeter

No agents, SDKs, or scripts run in your environment. The only integration is an API key you generate and can revoke at any time.

Public URLs only

OpenGraph+ fetches only the pages you submit. Private, reserved, and cloud metadata IP ranges are blocked at the network layer, so it cannot reach internal services.

Minimal data footprint

No passwords. No payment data. No page content. We render a screenshot, extract the Open Graph tags, and discard the HTML.

Encrypted and isolated

TLS in transit, encryption at rest, and every query scoped to a single tenant. There is no shared namespace between customers.

Compliance
SOC 2 Type II
Not certified
ISO 27001
Not certified
Regulated data processed
None
Your SOC 2 / ISO scope
Not affected
Breach notification
≤ 72 hours

Talk it through with a human

A security review that needs a real answer, a questionnaire to complete, or a control to walk through? Reach a person on our team, not a bot.