Oceanir

Physical inference, starting with geolocation

How we protect the images and evidence your team sends us: our compliance status, the controls in place, who processes data on our behalf, and the documents a security review needs.

Controls

Infrastructure security

ControlStatus
  • Data encrypted in transit

    All data in transit to and from Oceanir is encrypted with TLS 1.2 or higher.

  • Data encrypted at rest

    Databases and file storage that hold customer data are encrypted at rest.

  • Managed cloud hosting in the US

    Production runs on managed cloud infrastructure in a US region.

  • API access denied by default

    Every API route requires an authenticated session or API key unless it has been deliberately made public. New routes are private until opened.

  • Rate limiting and abuse blocking

    Requests are rate limited, and clients that show abusive patterns are blocked automatically.

  • Secret keys kept server-side

    Secret keys for paid services stay on our servers and are never sent to the browser. Only publishable map keys, which are designed to be public, are used in the browser.

Organizational security

ControlStatus
  • Least-privilege access

    Access to customer data is role-based and limited to personnel with a documented business need.

  • Confidentiality agreements

    Everyone authorized to process customer data is bound by a written duty of confidentiality that continues after their engagement ends.

  • Security training

    Personnel with access to customer data receive data protection and security training appropriate to their role.

  • Background screening

    Personnel with access to customer data are screened where applicable law permits.

Product security

ControlStatus
  • Audit logging

    Administrative and API access to customer data is logged.

  • Breached passwords rejected

    New passwords are checked against known data breaches and rejected if they appear in one.

  • Passkeys and Google sign-in

    Accounts can sign in with a passkey or with Google instead of a password.

  • Bot protection on sign-up

    Account sign-up is protected by an automated bot challenge.

  • Content security policy

    Every page is served with a strict content security policy and security headers that limit which scripts and sources can run.

Internal security procedures

ControlStatus
  • Incident response procedures

    Incident response procedures are documented, including notification timelines.

  • Breach notification within 24 hours

    If a breach affects customer data, the customer is notified within 24 hours of Oceanir becoming aware of it.

  • Security assessments

    Systems are assessed for security issues regularly, and identified vulnerabilities are remediated.

  • Encrypted backups

    Backups are encrypted, access-controlled, and accessed only for disaster recovery.

  • Service monitoring

    Every customer-facing service is checked every 2 minutes, with results published at status.oceanir.ai.

Data and privacy

ControlStatus
  • Analysis from visual content only

    Analysis reads what the image shows. It does not use the location metadata that cameras and phones can embed in files.

  • Saved history can be switched off

    A workspace can turn saved history off. It is enforced on our servers for the web app and the API: with it off, images and results are not stored.

  • Return or deletion on request

    On request, or when an agreement ends, customer data is returned in a machine-readable format or deleted, at the customer's choice, and sub-processors do the same.

  • No sale of personal information

    Personal information is never sold, and never used for cross-context behavioral advertising.

  • Sub-processor change notice

    Customers get 30 days notice before a new category of sub-processor is engaged, and may object.

  • Data Processing Agreement

    A Data Processing Agreement, including Standard Contractual Clauses for international transfers, is available to every customer.