HIPAA-ready. BAA available.
Offendersearch is built for compliance-sensitive, regulated customers — healthcare and home care, staffing and recruiting, and background-screening providers. We back that with real security controls and a Business Associate Agreement for eligible enterprise accounts.
We will sign a BAA with eligible enterprise customers
If you handle protected health information (PHI) and process it through the Offendersearch API — for example, screening patients, caregivers, or home-care staff — we will enter into a Business Associate Agreement that governs how we handle that data on your behalf. The BAA sets out permitted uses, safeguards, breach-notification obligations, and each party’s responsibilities.
- Available to eligible enterprise accounts that process PHI through the API.
- Scoped to your use case during procurement — no boilerplate you can’t map to.
- HIPAA compliance is a shared responsibility; the BAA defines each side’s obligations.
- Backed by the security controls documented below, not just paperwork.
Our security posture
An honest view of the controls in place today and where we’re investing. We describe our posture and roadmap — we don’t claim certifications we don’t hold.
Encryption in transit & at rest
All API traffic is served over TLS. Data stored by the platform — including customer records and generated reports — is encrypted at rest using industry-standard AES-256.
Least-privilege access controls
Internal access to production data is role-scoped and granted on a need-to-know basis. Administrative actions are gated behind authentication and reviewed periodically.
Per-account API keys, hashed at rest
Each account gets its own API keys. Secrets are stored as one-way hashes — we never keep the raw key — so a database read can never expose a usable credential. Keys can be rotated or revoked at any time.
Audit logging
API requests are logged with account, timestamp, and endpoint so activity can be reviewed and reconciled. Usage is visible to account owners in the dashboard.
Data retention & freshness controls
Registry data carries lastCheckedAt and configurable freshness tiers, and customer-submitted identifiers are retained only as long as needed to serve requests and support. Retention terms can be set contractually.
Tenant isolation
Every request is authenticated to a single account, and data access is scoped per tenant so one customer can never read another customer’s keys, usage, or reports.
Incident response & breach notification
We maintain an incident-response process for security events. Where a BAA is in place, breach-notification timelines and responsibilities are defined contractually so you know exactly what to expect and when.
Secure development lifecycle
Changes go through code review and automated checks before release, and third-party dependencies are monitored for known vulnerabilities so fixes ship promptly.
Encrypted backups & resilience
Platform data is backed up on a regular schedule using encrypted storage, so records and reports can be recovered without exposing data at rest.
A formal SOC 2 examination is in progress. We’re glad to walk procurement teams through our current controls and roadmap under NDA. Developers can see how auth, per-key hashing, and audit logging work in the API documentation.
What we process, and what we return
Two kinds of data flow through the API. Knowing exactly what each one is makes compliance review straightforward.
- Public-record registry data
- The offender records we return are aggregated from official government sex-offender registries. This is public-record data published by the states, DC, and US territories — it is not sourced from any private or protected dataset.
- Identifiers you submit
- To run a search you send us query inputs — typically a name and, optionally, date of birth or location. If that data is PHI in your hands (for example, a patient or applicant record), a signed BAA governs how we process it on your behalf.
- What we return
- Matches are public-record data, tagged with the originating registry and a link back to the official source, plus a match-confidence score. Results are informational and are not a consumer report.
- Hosting & subprocessors
- The platform runs on reputable US-based cloud infrastructure with encryption in transit and at rest. We keep the list of subprocessors that handle data on our behalf to a minimum and can provide it, along with data-residency details, during procurement or under a BAA.
Compliance questions, answered
Will Offendersearch sign a BAA?
Yes. Offendersearch will enter into a Business Associate Agreement with eligible enterprise customers who handle protected health information (PHI) in connection with our API. Request one through sales and we will scope it to your use case.
Is Offendersearch HIPAA compliant?
Offendersearch is built to support HIPAA-regulated workflows: encryption in transit and at rest, least-privilege access, hashed per-account API keys, audit logging, and tenant isolation, backed by a signed BAA. HIPAA compliance is a shared responsibility — the BAA defines each party’s obligations for the PHI you process through the API.
Do you hold a SOC 2 report?
A formal SOC 2 examination is in progress. We do not claim a completed SOC 2 report or certification we do not yet hold; we are happy to share our current security posture and roadmap under NDA during procurement.
What data does the API actually process?
Public-record registry data that we aggregate from official government sources, plus the identifiers you submit to run a search (such as name and date of birth). Results are public-record data and are not a consumer report.
How is my API key protected?
Each account gets its own API keys, and secrets are stored only as one-way hashes — we never keep the raw key, so a database read can never expose a usable credential. Keys can be rotated or revoked at any time, and the full secret is shown only once, at creation.
How do you handle a security incident?
We maintain an incident-response process for security events. Where a BAA is in place, it defines breach-notification timelines and each party’s responsibilities, so notification obligations are contractual rather than best-effort.
Where is data hosted, and who are your subprocessors?
The platform runs on reputable US-based cloud infrastructure with encryption in transit and at rest. We keep subprocessors to a minimum and can share the current list and data-residency details during procurement or under a BAA.
Are there jurisdiction restrictions I should know about?
Some jurisdictions restrict commercial use of registry data; use is subject to our acceptable-use terms and applicable law, accepted at onboarding.
Ready to talk compliance?
Request a BAA or get our security posture in front of your procurement team.