Netstate

Data Security

Last reviewedAugust 21, 2026

Netstate handles public records, not consumer financial accounts — but the platform, customer data and search activity are still secured to a commercial standard. This page is our security policy: it summarizes the data security and information security controls in place, and how to reach us if you find a problem. We describe only what is actually in place; certifications held by our infrastructure providers are attributed to them, not claimed as our own.

How do we protect data and ensure data protection?

Our data security measures aim to keep the platform available and to prevent unauthorized access to customer data, preserving data integrity in storage and transit. Access controls, encryption and cloud security combine into a layered set of security controls across production systems.

Hosting
Cloudflare Workers — Cloudflare's platform holds SOC 2 Type II and ISO 27001 certifications (Cloudflare's own, not ours)
Encryption in transit
TLS on all connections
Encryption at rest
Stored with our infrastructure providers, who encrypt at rest as part of their platforms
Payments
Handled by Paddle, our merchant of record — card details never touch Netstate servers
Access control
Role-based, least-privilege access management restricts production systems to authorized users, with multi-factor authentication on sensitive access

What is our compliance posture?

Netstate is not a consumer reporting agency under the Fair Credit Reporting Act. Our data is sourced from public records and is intended for research and due diligence, not for FCRA-regulated decisions on credit, employment, insurance or housing.

Netstate does not currently hold its own SOC 2 or ISO certification. Data handling for users is described in the privacy policy.

How do I report a vulnerability?

If you believe you have found a security issue, email hello@netstate.co with “Security report” in the subject and steps to reproduce. We acknowledge reports within two business days and do not pursue action against good-faith research. Reports feed our incident response: we triage each security incident, confirm impact and remediate before closing it out.