◆ Security & Data Handling

How we handle your data and your subject's data.

Recon Intelligence collects only publicly available OSINT signals. Here's exactly what we collect, how long we keep it, and how you can request deletion.

Last updated: August 16, 2026

01 · Collection Scope

What Recon Collects

Every signal Recon uses is publicly available. No private accounts, no gated communities, no purchased consumer PII.

Sources we use

  • Public social profiles: LinkedIn, Instagram, Twitter/X, TikTok, Facebook, YouTube, Reddit — collected via public web scraping and public API endpoints.
  • Public business listings: Google Maps, Crunchbase, SEC EDGAR (where relevant), Facebook Ad Library metadata.
  • Public review platforms: Google, Yelp, Trustpilot.
  • Publicly-indexed web content: news articles, press releases, company blog posts, and other content Google and other search engines already index.
Note: "Public" here means content available without authentication. If a signal requires logging in, joining a private community, or paying a data broker for consumer PII, Recon does not use it.
02 · Explicit Exclusions

What Recon Does NOT Collect

These are hard lines. They apply on every SKU — Lite, Standard, and Monitor — with no exceptions.

  • No private DMs or gated content. If it requires a login to view, Recon does not touch it.
  • No dark-web breach data on the Recon SKU. Breach and credential intelligence is a separate Cyberharpoon service governed by different consent requirements. Recon does not include it.
  • No purchased marketing or consumer databases. We do not buy PII lists, consumer household data, or aggregated identity graphs.
  • No cookie-based tracking on identified individuals. Recon does not follow subjects across the web with cookies or fingerprinting.
  • No wiretap or intercepted communications, ever. Under any circumstance.
03 · Retention

Data Retention

Different data classes have different retention windows. All windows are enforced automatically; no data is retained "indefinitely."

  • Monitor subscription report content: retained for the duration of the Monitor subscription plus 90 days after cancellation, then permanently deleted.
  • Lite / Standard one-time reports: retained for 12 months from delivery, then permanently deleted. Customers may request earlier deletion at any time.
  • Raw intermediate collection data (scraped social posts, API responses used to build the report): retained for 30 days for QA and audit purposes, then deleted.
  • Customer account data (email address, business identifier submitted at order time): retained per Stripe payment record requirements so we can honor refunds, tax obligations, and financial audit trails.
04 · Deletion Rights

Deletion Rights

Any customer, and any subject of a report with proven standing, can request deletion.

  • Customers can request deletion of their reports and associated collection data at any time by emailing info@dataflame.ai.
  • Subjects of a report (even if not the customer) can request deletion under the same terms if they can prove standing — a subject-access-request-style process. Verification is typically a domain-matched email, corporate letterhead, or a validated LinkedIn identity.
  • Response time: deletion is completed within 30 days of a validated request. Where a Stripe payment record must be retained for financial audit, only the operational report data is deleted; the payment metadata is kept per Stripe's retention requirements.
05 · Location & Access

Data Location & Access

Where the data lives, who can touch it, and what runs on the pages you see.

  • Infrastructure region: Reports are generated on infrastructure hosted in the United States.
  • Access controls: Access to raw collection data is limited to Cyberharpoon operational staff. Role-based access, MFA required for operator accounts.
  • Report dashboard analytics: No third-party analytics tracking on Recon report URLs. No Google Analytics on the dashboard, no Meta Pixel, no third-party session-replay or SDK.
  • Marketing site analytics: The public recon.dataflame.ai marketing site currently ships with no third-party analytics scripts — no Google Analytics, no Meta Pixel, no third-party SDKs. Only standard Netlify edge server logs (IP, user-agent, request path) are retained per Netlify's infrastructure defaults.
Transparency note: If we later add first-party analytics (privacy-preserving, cookieless), this section will be updated with the specific tool name before deployment.
06 · Compliance Posture

Compliance Posture

Honest statement of where we are, not where we'd like to be. Every claim below is defensible today.

  • SOC 2: Recon Intelligence is aligned with SOC 2 Trust Service Criteria principles (Security, Availability, Confidentiality). A formal SOC 2 audit is not yet complete. We will not claim certification until an independent auditor has issued a report.
  • GDPR: For EU-subject reports, we honor Article 17 (right to erasure) requests via the deletion process above.
  • CCPA: California residents can exercise deletion and access rights by emailing info@dataflame.ai.
  • HIPAA: Not HIPAA-compliant. Do not submit reports involving protected health information. If a report subject's business handles PHI, only public-facing information is collected; nothing involving PHI enters Recon.
  • PCI-DSS: Not directly PCI-DSS certified. All payment processing is handled entirely by Stripe (PCI-DSS Level 1). No cardholder data touches Recon systems.
07 · Enterprise

Enterprise Data Handling

For engagements above the standard SKUs, we can operate under bespoke terms.

  • Signed DPA + mutual NDA: Enterprise engagements at $10K+ annual value can be conducted under a signed Data Processing Agreement and mutual NDA.
  • Custom retention: Shorter retention windows, faster deletion SLAs, or extended retention for regulated recordkeeping can be negotiated case by case.
  • Data residency: Non-US infrastructure options can be discussed for enterprise contracts.
  • Access-control requirements: Named-analyst access, audit logging exports, and MFA / SSO integration for shared dashboards are accommodated on a case-by-case basis.
  • Contact: info@dataflame.ai to open a DPA discussion before purchase.
08 · Security Practices

Security Practices

The operational controls that back up the policy statements above.

  • Payment processing: Stripe. PCI-DSS Level 1 is handled entirely by Stripe, not by Recon. Cardholder data never touches our systems.
  • Report delivery: HTTPS-only. Lite and Standard reports are delivered via signed URLs with expiration.
  • Infrastructure: Marketing site is hosted on Netlify. The report backend is fronted by a Cloudflare tunnel. Standard TLS in transit, at-rest encryption on managed cloud storage.
  • Access controls: Role-based access to production data. MFA required for operator accounts.
  • Incident response: Any confirmed data breach affecting customer data will be notified within 72 hours per GDPR standards — extended to all customers as a matter of policy, not just EU subjects.

Have specific data-handling requirements?

If you're evaluating the Monitor tier or a larger enterprise engagement and need custom retention, data residency, DPA, or NDA terms — let's talk before you buy.

Discuss enterprise requirements — info@dataflame.ai