Data Sourced from Official State Registries
Rather than depending on intermediary data providers, Offenders.io sources data from 184 U.S. registry jurisdictions spanning all 50 states, DC, U.S. territories, and tribal jurisdictions. Our data pipeline ingests publicly available records from official registries, ensuring every record reflects the latest official data — not stale snapshots from secondary databases.
- 184 state, territory, and tribal jurisdictions — authoritative public registry sources
- Real-time synchronization — not monthly or quarterly batch imports
- 70+ schema fields per state — the deepest state-level data coverage available
- Source-verified records — every record traceable to its official registry origin
Data Accuracy & Freshness
Data accuracy is non-negotiable for compliance-critical applications. Our Extensive Mode performs real-time lookups against state registries at query time, guaranteeing registry-current results for every API call. Standard mode uses continuously synchronized data with sub-200ms response times.
Standard ModeContinuously synced data, sub-200ms responses
Extensive ModeReal-time registry lookup at query time
Data Governance & Privacy
We treat data governance as a core product requirement, not an afterthought. All data handling follows strict policies designed for compliance-sensitive environments.
- Layered retention — operational telemetry remains minimized. Eligible authenticated, non-HIPAA, non-no-log Search evidence is application-encrypted with a per-request key, kept in a 30-day hot tier, and sealed into a verified private archive with a 400-day lifecycle. Longer preservation requires an explicit, audited legal hold
- HIPAA and no-log boundaries — accounts with a server-verified HIPAA or no-log flag are excluded from exact-query forensic capture. Minimum security, authentication, billing-integrity, and compliance metadata remains available without raw search values
- PII handling — ordinary request telemetry is minimized and sanitized for operational monitoring, rate limiting, and abuse prevention. Query data is not sold or disclosed for advertising
- Data isolation — multi-tenant architecture with strict logical separation. No customer can access another customer's query history or usage data
- Deletion requests — customers can request deletion of eligible query and account data, subject to security, billing, contractual, legal-hold, and other applicable retention obligations
- Subprocessors — Cloudflare (edge compute, CDN, DDoS protection), Google Cloud Platform (infrastructure). Full subprocessor list available on request
Responsible Use & Legal
Sex offender registry data carries significant legal and ethical responsibilities. We require all API consumers to adhere to our acceptable use policy and applicable laws.
- Candidate public records — standard API results are sourced from official public registries and are not identity-verified, risk-scored, adjudicated, or presented as eligibility recommendations
- Standard-service boundary — self-service, trial, map, batch, and standard API access is not offered as a consumer-reporting service and does not automatically include FCRA-regulated use
- FCRA-regulated workflows — approved CRA and Enterprise partners may use separately enabled regulated access with permissible-purpose and recipient traceability, source verification procedures, request-level evidence, and consumer file and dispute operations under written scope. Learn about FCRA Partner Access
- Downstream responsibilities — Offenders.io supplies source-based public-record data and does not make hiring or eligibility decisions, provide pass/fail adjudication, or operate employer pre-adverse or adverse-action workflows
- Permissible purposes — API access is restricted to lawful purposes including public safety applications, compliance monitoring, research, and community awareness
- Anti-discrimination — customers must not use registry data to discriminate in housing, employment, or services beyond what is required by law
- Redistribution — raw data redistribution or resale is prohibited without a separate data licensing agreement
Infrastructure & Reliability
Offenders.io runs on globally distributed edge infrastructure with built-in redundancy. Our architecture is designed for the uptime and performance requirements of enterprise compliance workflows.
- 99.9% uptime SLA — live status page with real-time and historical uptime data
- Sub-200ms average response time — verified on public status dashboard
- Global edge network — deployed across 300+ Cloudflare edge locations worldwide
- Automatic failover — no single point of failure, multi-region redundancy
- Encryption at rest — all stored data encrypted using AES-256
- Backup & disaster recovery — automated daily backups with geographic redundancy. RPO < 24 hours, RTO < 4 hours
Security
Security is built into every layer of our stack — from network edge to application logic to data storage.
- TLS 1.3 encryption — all API traffic encrypted in transit, HSTS enforced
- API key authentication — unique keys with per-key usage tracking and rate limiting
- IP allowlisting — available for enterprise customers to restrict API access to known IPs
- BAA-supported enterprise workflows — available only for approved enterprise customers under a separately executed Business Associate Addendum
- FCRA-regulated partner workflows — available only under approved permissible purpose, written agreement, separately enabled access, and applicable jurisdictional scope
- DDoS protection — enterprise-grade edge security via Cloudflare
- Dependency scanning — automated vulnerability scanning on all dependencies
- Secure development — code review required for all changes, automated testing in CI/CD pipeline
- SOC 2 Type II Compliant — controls covering security, availability, and confidentiality were independently audited by a third party
Incident Response
We maintain a documented incident response process to ensure rapid detection, containment, and communication for any security or availability event.
- Detection — automated monitoring with alerting on anomalies, error rate spikes, and unauthorized access attempts
- Notification timeline — affected customers notified within 72 hours of confirmed data breach, within 24 hours for critical incidents
- Security contact — report vulnerabilities to security@offenders.io
- Post-incident review — root cause analysis and remediation published for all significant incidents
- Status page — real-time incident updates at status.offenders.io
Compliance & Audit Report
Our SOC 2 Type II audit report documents the controls and operating practices that support security, availability, and confidentiality for enterprise customers. The report is available in the Trust Portal.
- SOC 2 Type II Compliant — independently audited by a third party against the AICPA Trust Services Criteria; the audit report is available in the Trust Portal
- HIPAA / BAA support — available only for approved enterprise customers under a separately executed Business Associate Addendum. Self-service accounts are not authorized to submit PHI or ePHI
- FCRA Partner Access — separately enabled regulated public-record workflows for approved CRA and Enterprise partners, with consumer file and dispute support. Review program scope
- CCPA / CPRA — we support California Consumer Privacy Act obligations including data access, deletion, and opt-out requests
- Data Processing Agreement — standard DPA available for enterprise customers on request
Status & Transparency
We believe in radical transparency about our operational performance. All uptime and response time data is publicly available.
- Public status page — status.offenders.io with real-time monitoring
- Historical uptime — 30-day uptime history publicly visible
- Response time tracking — P50 latency metrics published continuously
- Incident history — all past incidents documented with root cause and resolution
Enterprise Support
Enterprise customers receive dedicated support, volume pricing, priority access to new features, and access to security documentation through our external trust portal. We work directly with compliance teams, security departments, and engineering organizations at scale.