Skip to content
New Venue Data
Security

Security, stated honestly.

New Venue Data resells public business-records dataand holds a small amount of account data. Below is exactly how we secure it today — and, just as importantly, what is still planned for enterprise. We don't claim certifications or controls we haven't earned.

What's in place today

How we handle data + access

A small, focused surface: public-records data, a REST API with hashed keys, and a single administrator.

Encrypted in transit

Every request to the site and API is served over HTTPS/TLS. The data we serve is public business-entity records — no consumer PII, SSNs, or credit data — so the sensitivity of what we handle is inherently low.

Trusted infrastructure

Hosted on Vercel, which maintains SOC 2 Type II compliance, with isolated production builds and no public access to internal data files. We are transparent that the platform is SOC 2 — New Venue Data is not yet independently audited.

API key security

API keys are stored as SHA-256 hashes only — we never store or can recover your raw key. Keys are scoped to a plan, revocable, and can be re-issued on request. Per-key rate limits are applied to each request.

Public-records data only

We process Florida (and Texas) business-license public records — no consumer data. Sources refresh daily; we attribute each source and follow its terms. This keeps us outside FCRA and minimizes the data we hold.

Account access

Administrative access is limited to the founder and protected by strong authentication. SSO/SAML, scoped team roles, and tamper-evident audit logging are on the roadmap for enterprise customers.

Reliability

Served from Vercel's global edge; the dataset is version-controlled and regenerated daily from source. Formal uptime SLAs, point-in-time backups, and on-call monitoring are available for enterprise — talk to us about requirements.

Compliance

Where each framework actually stands

Stated plainly — what is true by design, what comes from our infrastructure, and what is available on request.

FCRA-safe by design

Business-entity public records only. We are not a consumer reporting agency under the FCRA.

By Design

Public records (Ch. 119)

All data originates from official Florida/Texas public-records sources; not affiliated with or endorsed by any state agency.

By Design

SOC 2 (infrastructure)

Hosted on Vercel, a SOC 2 Type II platform. New Venue Data itself is not yet independently SOC 2 audited.

Infrastructure

GDPR / CCPA

We sell business-entity data, not consumer data. We honor applicable data requests and can provide a DPA on request.

On request

Need security documentation for a procurement review? Email austin@newvenuedata.com and I'll share exactly what we have — no overstatement.

Responsible disclosure

If you believe you've found a vulnerability in our site or API, please email a detailed report. I'll acknowledge it within one business day, keep you updated as I investigate, and credit researchers who follow good-faith disclosure.

austin@newvenuedata.com

Get this week's new Florida venues.

No contracts. Cancel any time. County plan from $149/month.