OpenGraph+ runs outside your infrastructure, reads only the public pages you point it at, and stores almost nothing. Not much for a security review to snag on.
No agents, SDKs, or scripts run in your environment. The only integration is an API key you generate and can revoke at any time.
OpenGraph+ fetches only the pages you submit. Private, reserved, and cloud metadata IP ranges are blocked at the network layer, so it cannot reach internal services.
No passwords. No payment data. No page content. We render a screenshot, extract the Open Graph tags, and discard the HTML.
TLS in transit, encryption at rest, and every query scoped to a single tenant. There is no shared namespace between customers.