Security, stated honestly.
New Venue Data resells public business-records dataand holds a small amount of account data. Below is exactly how we secure it today — and, just as importantly, what is still planned for enterprise. We don't claim certifications or controls we haven't earned.
How we handle data + access
A small, focused surface: public-records data, a REST API with hashed keys, and a single administrator.
Encrypted in transit
Every request to the site and API is served over HTTPS/TLS. The data we serve is public business-entity records — no consumer PII, SSNs, or credit data — so the sensitivity of what we handle is inherently low.
Trusted infrastructure
Hosted on Vercel, which maintains SOC 2 Type II compliance, with isolated production builds and no public access to internal data files. We are transparent that the platform is SOC 2 — New Venue Data is not yet independently audited.
API key security
API keys are stored as SHA-256 hashes only — we never store or can recover your raw key. Keys are scoped to a plan, revocable, and can be re-issued on request. Per-key rate limits are applied to each request.
Public-records data only
We process Florida (and Texas) business-license public records — no consumer data. Sources refresh daily; we attribute each source and follow its terms. This keeps us outside FCRA and minimizes the data we hold.
Account access
Administrative access is limited to the founder and protected by strong authentication. SSO/SAML, scoped team roles, and tamper-evident audit logging are on the roadmap for enterprise customers.
Reliability
Served from Vercel's global edge; the dataset is version-controlled and regenerated daily from source. Formal uptime SLAs, point-in-time backups, and on-call monitoring are available for enterprise — talk to us about requirements.
Where each framework actually stands
Stated plainly — what is true by design, what comes from our infrastructure, and what is available on request.
FCRA-safe by design
Business-entity public records only. We are not a consumer reporting agency under the FCRA.
Public records (Ch. 119)
All data originates from official Florida/Texas public-records sources; not affiliated with or endorsed by any state agency.
SOC 2 (infrastructure)
Hosted on Vercel, a SOC 2 Type II platform. New Venue Data itself is not yet independently SOC 2 audited.
GDPR / CCPA
We sell business-entity data, not consumer data. We honor applicable data requests and can provide a DPA on request.
Need security documentation for a procurement review? Email austin@newvenuedata.com and I'll share exactly what we have — no overstatement.
Responsible disclosure
If you believe you've found a vulnerability in our site or API, please email a detailed report. I'll acknowledge it within one business day, keep you updated as I investigate, and credit researchers who follow good-faith disclosure.
austin@newvenuedata.comGet this week's new Florida venues.
No contracts. Cancel any time. County plan from $149/month.