Security & Compliance

AvisRadar is built to protect your data with the highest security standards. Here's how we secure your competitive intelligence.

🔒
HTTPS / TLS 1.3
End-to-end encryption
🇪🇺
GDPR Compliant
EU regulation
🔑
Secure Auth
JWT httpOnly + bcrypt
💳
Stripe PCI DSS
Zero banking data stored

Architecture & Hosting

ComponentProviderLocation
ApplicationRailway (US infrastructure, encrypted transit)US-West
DatabaseEmbedded SQLite (no exposed DB server)Same instance
PaymentsStripe PCI DSS L1Global
EmailResend (SPF/DKIM/DMARC)US/EU
AI AnalysisAnthropic (Claude API) SOC 2US
Public review scrapingApify / OutscraperEU/US

All communications between components are encrypted (TLS 1.2+). No banking data ever touches our servers — Stripe handles 100% of payment processing.

Authentication & Access Control

Data We Collect

What we collect

DataPurposeRetention
Email, nameAccount & reportsSubscription duration + 30 days
Google Maps Place IDPublic review collectionSubscription duration
Public Google reviewsCompetitive analysisSubscription duration

What we do NOT collect

GDPR Compliance

AvisRadar complies with the General Data Protection Regulation (GDPR). You have the following rights at any time:

To exercise your rights: hello@avisradar.app — response within 48 business hours.

AI Processing

Reports are generated by Claude (Anthropic). Data sent to the Claude API:

Sub-processors

Sub-processorRoleCompliance
StripePaymentsPCI DSS Level 1, SOC 2
AnthropicAI analysisSOC 2 Type II
ResendEmail deliverySPF/DKIM/DMARC, GDPR
RailwayHostingSOC 2
ApifyPublic review collectionGDPR

Vulnerability Reporting

If you discover a security vulnerability, contact us immediately at hello@avisradar.app with subject "[SECURITY]". We commit to:

Questions about security?

Our team responds within 48 hours to all compliance and security inquiries.

Contact us