Built for compliance-sensitive teams
Security, privacy, and jurisdiction-aware use are core to the product — not an afterthought. Here is how Offendersearch handles them.
Encryption everywhere
TLS in transit, encryption at rest, and hashed API keys shown once at creation.
Least-privilege access
Per-key scopes limit which freshness tiers and add-ons a key can use; rotate or revoke instantly.
SOC 2-aligned controls
Access logging, change management, and monitoring aligned to SOC 2 practices.
HIPAA-ready + BAA
A BAA path for enterprise customers whose screening touches protected health workflows.
Jurisdiction-aware use
Some jurisdictions restrict commercial use of registry data; use is subject to our acceptable-use terms and applicable law, accepted at onboarding.
Provenance & audit
Every record links to its official source with a lastCheckedAt timestamp for a defensible audit trail.
Legal & acceptable use
Registry data is aggregated from official state and national sources. Some jurisdictions restrict commercial use of registry data; use is subject to our acceptable-use terms and applicable law, accepted at onboarding. See our coverage & legal notes.
Offendersearch is not a consumer reporting agency and results are not a consumer report; do not use them for FCRA-covered decisions without appropriate process.
Trust FAQ
Is Offendersearch HIPAA-compliant?
We follow a HIPAA-ready path and offer Business Associate Agreements (BAAs) to enterprise customers whose workflows require one, such as healthcare and home-care screening.
How is data encrypted?
All traffic is encrypted in transit with TLS, and data at rest is encrypted. API keys are hashed at rest and shown in full only once at creation.
Do you restrict how registry data can be used?
Some jurisdictions restrict commercial use of registry data; use is subject to our acceptable-use terms and applicable law, accepted at onboarding.