Separation between customers#
Every customer’s data is separated from every other customer’s, and that separation is enforced in the database itself rather than only in application code.
Reporting a security issue#
If you believe you have found a security vulnerability in Expanding Ranks, we want to hear about it.
How to reach us: use the contact form on our Support page and choose the security topic.
Please include:
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce it
- Any proof-of-concept code, screenshots, or logs that would help us confirm and fix it
- Your contact information, so we can follow up with questions
What you can expect from us:
- We will acknowledge a good-faith report within three (3) business days.
- We will give you an initial assessment of severity and next steps within ten (10) business days.
- We will keep you informed as we investigate and fix confirmed issues, and we will let you know once a fix has shipped.
- We do not currently operate a paid bug bounty program. We are glad to publicly credit researchers who report responsibly, if they would like that.
What we ask of researchers:
- Give us a reasonable opportunity to investigate and fix an issue before disclosing it publicly.
- Test only against your own account. Do not access, modify, or download another customer's data.
- Do not run denial-of-service testing, spam our users, or use social engineering against our staff or customers.
- Do not use a vulnerability beyond what is necessary to demonstrate it. Stop and report as soon as you have confirmed impact.
- If you find candidate or customer data you were not expecting to see, stop immediately, do not copy or retain it, and tell us.
We will not pursue legal action against researchers who make a good-faith effort to follow these guidelines, report through the channel above, and avoid privacy violations, data destruction, or service disruption.
Infrastructure and sub-processors#
Application data is held by Neon, our managed database provider, and is stored in a United States region. Neon itself runs on Amazon Web Services, in an Amazon data center in Ohio, which is why an Amazon region is the honest answer to where your data sits. Nothing of ours runs on Amazon directly. Requests to our site first pass through Cloudflare, our security and traffic layer, which runs a global network and does not store your data.
The other companies that handle this application's data on our behalf are our sub-processors. We keep a current list of every one of them, with what each handles and where, and we will send it to you on request. Use the contact form on our Support page. You can also read it without asking, at Sub-processors. If you are a customer, we notify you in writing before any sub-processor changes, so you do not have to watch that page.
What we have not yet agreed with them in writing, said plainly rather than left for you to discover. We do not yet have a data processing agreement with either sub-processor, and we do not yet have a written commitment from either that they will not use what we send them to train or improve their own models. Expanding Ranks LLC was formed on September 25, 2026 and no vendor agreement has been executed yet. We would rather tell you that than let you assume otherwise, and we will say so here as each one is signed.
What we do commit to ourselves is separate and it is in force now. We do not use your data to train or improve general-purpose models, we do not share it between customers, and we do not use it for advertising. That is our own undertaking to you in our Privacy Policy, and it does not depend on a vendor agreement. How we handle your data, what we collect, and how long we keep it are set out in full there.
Where we are today#
Expanding Ranks is in development and is not yet generally available. We do not hold SOC 2, ISO 27001, or any other third-party security certification, and no independent penetration test of Expanding Ranks has been completed as of the date of this statement. We are not going to claim otherwise to make this page read better. As we move toward general availability, we expect to pursue formal third-party security assessment, and we will update this page when we do.
Contact us#
Security reports: the contact form on our Support page. Everything else: see Support.