Security & compliance, self-serve
Public policies, control summaries, and a direct path for DPAs or vendor questionnaires — updated July 26, 2026. Built so procurement does not need a 100-question email thread to start.
Compliance status
Honest status only. We do not put SOC 2 or ISO badges on this page until we hold a current attestation.
- Public security & privacy policies
- AvailableSelf-serve on this site — no NDA required for the public pages.
- GDPR / privacy rights requests
- AvailableHandled via privacy@nichemaps.io as described in the Privacy Policy.
- PCI-DSS (card data)
- N/ANicheMaps never stores full card numbers; Stripe is PCI-DSS Level 1.
- SOC 2 Type II
- Not yetNot yet certified. We share our control overview and will update this when an attestation is available.
- ISO 27001
- Not yetNot yet certified. Same honest stance as SOC 2 — no fake badges.
Document library
Public pages are open to anyone. Request-only items go through security@nichemaps.io — useful when a buyer's process still wants a signed packet.
- Privacy Policy
What we collect, how we use it, retention, and your rights.
- Terms of Service
Accounts, acceptable use, subscriptions, and liability.
- Security overview
Encryption, access control, payments, and disclosure process.
- Refund Policy
Trialing the free catalog and how refunds are handled.
- Data Processing Addendum (DPA)
Standard DPA for customers who need a processor agreement.
- Vendor security questionnaire answers
SIG / CAIQ / custom security questionnaire responses.
Security controls
The short version for security reviews. Full write-up on the Security page.
- Encryption everywhere
- Your connection to NicheMaps is encrypted in transit, and the data we store is encrypted at rest.
- Least-privilege access
- Access to systems and customer data is limited to what is required to operate the product. Secrets are kept out of application code.
- Hardened hosting
- We run on a major cloud platform with isolation between components and ongoing security updates.
- Payment security
- Card details are handled entirely by Stripe, a PCI-DSS Level 1 provider. We never see or store your full card number.
- Minimal data collection
- We collect only what's needed to run your account. We never sell your personal data.
- Backups & resilience
- Core data is backed up for durability, and the service is designed for high availability.
Subprocessors
Third parties that may process customer account or usage data to run NicheMaps.
| Vendor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, compute, storage, email delivery (SES) | United States (and AWS regions we enable) |
| Stripe | Subscription billing and payment processing | United States / global Stripe regions |
| PostHog | Product analytics, session replay, and error capture | EU (eu.i.posthog.com) |
Common questionnaire answers
Enough for many security reviews to skip the first round of email. Need a full SIG or CAIQ filled? Use the request form below.
- Do you sell or share customer personal data?
- No. We do not sell personal data. We share it only with processors who help run the service (see subprocessors), under agreements that require them to protect it.
- Where is customer data hosted?
- Primary infrastructure is on Amazon Web Services. Analytics events go to PostHog's EU cloud. Card data is processed by Stripe and never stored by NicheMaps.
- Can we get a DPA or questionnaire filled out?
- Yes. Email security@nichemaps.io with your DPA or SIG/CAIQ/custom questionnaire. We aim to reply within two business days.
- How do you handle vulnerability reports?
- Email security@nichemaps.io with details and repro steps. Please give us a reasonable window to investigate before public disclosure.
- What customer data do you store?
- Account email and auth credentials, subscription/customer identifiers from Stripe, and basic usage logs needed to operate the product. See the Privacy Policy for the full list.
Request access
Prefer a direct note? security@nichemaps.io