Oceanir
Physical inference, starting with geolocation
How we protect the images and evidence your team sends us: our compliance status, the controls in place, who processes data on our behalf, and the documents a security review needs.
Controls
Infrastructure security
Data encrypted in transit
All data in transit to and from Oceanir is encrypted with TLS 1.2 or higher.
Data encrypted at rest
Databases and file storage that hold customer data are encrypted at rest.
Managed cloud hosting in the US
Production runs on managed cloud infrastructure in a US region.
API access denied by default
Every API route requires an authenticated session or API key unless it has been deliberately made public. New routes are private until opened.
Rate limiting and abuse blocking
Requests are rate limited, and clients that show abusive patterns are blocked automatically.
Secret keys kept server-side
Secret keys for paid services stay on our servers and are never sent to the browser. Only publishable map keys, which are designed to be public, are used in the browser.
Organizational security
Least-privilege access
Access to customer data is role-based and limited to personnel with a documented business need.
Confidentiality agreements
Everyone authorized to process customer data is bound by a written duty of confidentiality that continues after their engagement ends.
Security training
Personnel with access to customer data receive data protection and security training appropriate to their role.
Background screening
Personnel with access to customer data are screened where applicable law permits.
Product security
Audit logging
Administrative and API access to customer data is logged.
Breached passwords rejected
New passwords are checked against known data breaches and rejected if they appear in one.
Passkeys and Google sign-in
Accounts can sign in with a passkey or with Google instead of a password.
Bot protection on sign-up
Account sign-up is protected by an automated bot challenge.
Content security policy
Every page is served with a strict content security policy and security headers that limit which scripts and sources can run.
Internal security procedures
Incident response procedures
Incident response procedures are documented, including notification timelines.
Breach notification within 24 hours
If a breach affects customer data, the customer is notified within 24 hours of Oceanir becoming aware of it.
Security assessments
Systems are assessed for security issues regularly, and identified vulnerabilities are remediated.
Encrypted backups
Backups are encrypted, access-controlled, and accessed only for disaster recovery.
Service monitoring
Every customer-facing service is checked every 2 minutes, with results published at status.oceanir.ai.
Data and privacy
Analysis from visual content only
Analysis reads what the image shows. It does not use the location metadata that cameras and phones can embed in files.
Saved history can be switched off
A workspace can turn saved history off. It is enforced on our servers for the web app and the API: with it off, images and results are not stored.
Return or deletion on request
On request, or when an agreement ends, customer data is returned in a machine-readable format or deleted, at the customer's choice, and sub-processors do the same.
No sale of personal information
Personal information is never sold, and never used for cross-context behavioral advertising.
Sub-processor change notice
Customers get 30 days notice before a new category of sub-processor is engaged, and may object.
Data Processing Agreement
A Data Processing Agreement, including Standard Contractual Clauses for international transfers, is available to every customer.
