Plain-language summary
Datasets are delivered via secure links bound to the approved access request. Version control and an audit trail are recorded for every delivery. We don't host the data inside published pages, and access to operational systems is restricted to the people who need it.
This page describes app-visible practices. It is not an independent certification. Specific commitments and certifications marked [to confirm] are pending final review.
Dataset delivery
On approval of an access request, the dataset and its dossier are delivered via a secure link bound to that specific request. The link is scoped to the approved use and is not designed for general redistribution within an organisation; if more recipients need access, they each submit a request.
Audit trail
Every delivery is versioned and logged. When a new dataset version ships, the manifest records what changed and whether the change affects the licence posture. Buyers see this trail in the dossier; auditors can request the trail via the contact form.
Access control
Access to operational systems is limited to platform operators on a need-to-know basis. Provider material is segregated from buyer-side review surfaces. Specific control frameworks [to confirm — SOC 2 / ISO 27001] will be documented when applicable.
Data we hold
Access-request and submission contents, the dossiers attached to each listing, executed licences, and operational logs. We do not host dataset payloads inside public pages — only the descriptive metadata required to evaluate a listing is publicly visible.
Responsible disclosure
Security researchers are welcome to report findings via the contact form with subject Security. We acknowledge within one working day and work toward remediation in good faith. We do not pursue legal action against good-faith researchers acting within the bounds of this policy [to confirm — safe-harbour wording].