Planned
TRUST
How HangerSearch handles your archives.
We show live technical controls as Active, privacy and accessibility work as Building, and registry programs as Planned until they appear on a public list. We do not mark frameworks Verified or Compliant until that evidence exists.
Last updated: August 2026
Controls and programs
Planned
UK Extension and Swiss-U.S. DPF
Planned
CSA STAR Level 1
Building
GDPR
Building
CCPA / CPRA
Building
WCAG 2.2 AA
Active
TLS 1.2 / 1.3
Active
AES-256 encryption at rest
What each status means
- EU-U.S. Data Privacy Framework (Planned)
- DPF self-certification is only available to U.S. organizations under FTC or DOT jurisdiction, listed at dataprivacyframework.gov. We are not on that list. Cross-border transfers rely on our processors’ mechanisms (typically Standard Contractual Clauses), not a DPF claim.
- UK Extension and Swiss-U.S. DPF (Planned)
- The UK Extension and Swiss-U.S. DPF are add-ons to an active EU-U.S. DPF listing. They are not claimed until that listing exists.
- CSA STAR Level 1 (Planned)
- Level 1 is a CAIQ self-assessment submitted to the CSA STAR Registry (CAIQ v4.1 / CCM v4.1). We will publish the questionnaire and link the registry entry here when listed. Level 2 is a third-party audit and is later work.
- GDPR (Building)
- GDPR is a regulation, not a badge. Day-one posture: tenant isolation, retrieval-only processing of report text, a privacy notice, rights requests by email, and non-essential analytics off until consent (Global Privacy Control is treated as decline). Still to ship: records of processing, signed processor DPAs, and complete erasure across search indexes.
- CCPA / CPRA (Building)
- We do not sell personal information. Access, deletion, and correction requests: email us. Global Privacy Control is honored (analytics stay off). Still to ship: a “Do Not Sell or Share” control if sharing ever applies, and documented service-provider terms.
- WCAG 2.2 AA (Building)
- Marketing and product UI follow the design system: semantic structure, focus rings, reduced-motion, and minimum tap targets. We have not published a VPAT/ACR yet.
- TLS 1.2 / 1.3 (Active)
- Production traffic to hangersearch.com, api.hangersearch.com, and agent.hangersearch.com is served over HTTPS (TLS 1.2 or 1.3) via Cloudflare and Fly.io.
- AES-256 encryption at rest (Active)
- Customer PDFs in Cloudflare R2 and application data in MongoDB Atlas use AES-256 encryption at rest. Vector indexes on Qdrant Cloud are encrypted at rest by the provider.
Controls in production
Workspace isolation
Reports, collections, billing, object storage keys, and search indexes are scoped by organization. Your archive is not mixed with another customer’s.
Retrieval only
We find relevant historical report pages. We do not generate answers or summaries from your corpus.
Magic-link sign-in
Accounts use email magic links. We do not store passwords.
Self-host option
Teams with residency or air-gap requirements can run the same stack on their infrastructure.
Subprocessors
These providers process data to run HangerSearch. We do not sell personal information.
- CloudflareWeb app, DNS, and object storage (R2)
- Fly.ioAPI and search-agent compute
- MongoDB AtlasApplication and agent databases
- Qdrant CloudVector and lexical search indexes
- OpenAIEmbeddings and indexing/search model calls on extracted text
- ResendTransactional email (magic links)
- RazorpayCheckout and subscriptions
- Google Analytics, Microsoft Clarity, Reddit PixelMarketing measurement only after Accept, and never when Global Privacy Control is set
Transfers, DPA, and analytics
- Roles and DPA
- We are the processor for archives you upload and the controller for account and billing data. Email hello@hangersearch.com with subject “DPA request” for a Data Processing Agreement. Counsel must review it — we do not publish an unsigned template as if it were executed.
- International transfers
- Hosting data in the EU does not by itself protect a non-EU company from foreign lawful-access laws (the sovereignty gap). DPF is only for a U.S. organization under FTC or DOT jurisdiction that is listed on dataprivacyframework.gov. We are not listed. Transfers rely on our processors’ Standard Contractual Clauses. DPF does not replace a DPA and does not cover subprocessors that are not themselves listed.
- Analytics
- Google Analytics, Microsoft Clarity, and the Reddit Pixel are optional. They load only after Accept, and stay off when Global Privacy Control is set. First-party attribution in localStorage (campaign source) is not a third-party tracker. Sign-in session cookies are essential.
- Residency
- Teams that need data to stay on their network use self-host. We are not running a second EU application cluster. At sign-in we store the CDN country (Europe / US / other) so we can plan residency later. Search needs extracted text to embed and retrieve — customer-held zero-knowledge encryption of archives is not compatible with this product.
Privacy requests
Email hello@hangersearch.com with subject “Privacy request” for access, correction, or deletion of account and workspace data. We aim to respond within 30 days (GDPR) or 45 days (CCPA). Index purge for deleted workspaces is part of the GDPR program and is not fully automatic yet.
Email hello@hangersearch.comNext, not claimed
- Signed customer DPA and processor DPAs (Cloudflare, Fly, Atlas, Qdrant, OpenAI, Resend, Razorpay)
- Complete erasure across Mongo, R2, and Qdrant when a workspace is deleted
- CSA STAR Level 1 CAIQ v4.1 on the STAR Registry
- ISO 27001 if an EU buyer requires a cert; SOC 2 Type I then II for US buyers — both are audits
- DPF only after a U.S. FTC/DOT entity is listed on dataprivacyframework.gov
