OpenGraph+ runs outside your infrastructure, reads only the public pages you point it at, and stores almost nothing. Not much for a security review to snag on.
No agents, SDKs, or scripts run in your environment. The only integration is an API key you generate and can revoke at any time.
OpenGraph+ fetches only the pages you submit. Private, reserved, and cloud metadata IP ranges are blocked at the network layer, so it cannot reach internal services.
No passwords. No payment data. No page content. We render a screenshot, extract the Open Graph tags, and discard the HTML.
TLS in transit, encryption at rest, and every query scoped to a single tenant. There is no shared namespace between customers.
We run OpenGraph+ to the bar a formal audit would set: least-privilege access, encryption in transit and at rest, strict tenant isolation, and breach notice within 72 hours. We're not SOC 2 or ISO 27001 certified yet, but we hold that posture and take it every bit as seriously as a certified vendor would.
How OpenGraph+ protects your data
What we collect, how we use it, and where it goes
How your information is protected
What to expect from using our service
Third-party services that process data on our behalf
How OpenGraph+ started