Last updated

Trust center for domain intelligence.

Review access, lineage, privacy, security posture, and operational controls before Domain Atlas becomes part of a customer workflow.

  • Review access model, data lineage, privacy handling, security posture, and operational controls from one public trust page.
  • Use security, privacy, coverage, API docs, status, and contact pages as the follow-up paths for buyer and engineering review.
  • Confirm customer API keys, request metadata, source labels, health endpoints, browser headers, and retention boundaries before rollout.
  • Access model: Console review runs on a signed-in session. Automation uses Domain Atlas API keys, shown once and stored only as SHA-256 hashes.
  • Data lineage: Every profile section can expose endpoint, field path, source family, cache state, and coverage status.
  • Operational posture: Request IDs on every response, rate-limit responses with retry hints, browser security headers, and a public status page with live health checks.
  • API-key usage kept: Up to 400 days.
  • Audit events kept: Up to 730 days.
  • Deleted account restore: 30 days.
  • Subprocessor, Cloudflare: Hosting, storage, the edge network, and watchlist email sending.
  • Subprocessor, Stripe: Payments for Pro subscriptions. Card numbers go to Stripe, never to us.
  • Subprocessor, Google: Sign-in, when you choose to continue with Google.
  • Subprocessor, Licensed data service: Our licensed domain data service supplies the domain data behind every profile.
  • Compliance: Domain Atlas does not publish a third-party audit report (such as SOC 2) today; send security questionnaires to security@domainatlas.com.
  • Access model: Session access for the console, hashed customer API keys for data endpoints, and revocation from the key workspace. Route: Security review.
  • Operational controls: Request IDs on every response, rate-limit responses with retry hints, uncached account responses, browser security headers, and health endpoints that report status without exposing secrets. Route: Sales and support.
  • Data lineage: Visible endpoint, field path, source family, cache state, and coverage status for domain profile sections. Route: Sales and support.
  • Data handling: Internal credentials stay server-side, customer keys are shown once, and lookup activity is described in the privacy model. Route: Privacy and data.

Questions

How do we send a security questionnaire?

Email it to security@domainatlas.com, the security review channel on the contact page. Domain Atlas does not publish a third-party audit report (such as SOC 2) today, so the questionnaire is the way to review controls.

Where should security reviewers start?

Start with the security page: credential isolation, the API key lifecycle, request boundaries and browser headers, and how to report a vulnerability to security@domainatlas.com.

How does Domain Atlas explain data lineage?

Domain Atlas keeps endpoint, field path, source family, cache state, and coverage status close to profile values and summarizes that model on the coverage page.