Back to Home
Legal

Security

At OmniLegislation™, protecting your data and maintaining the integrity of our platform is a core priority.

Last Updated: August 12, 2026

DigitalTreehouse LLC, d/b/a OmniLegislation™ (“we,” “us,” or “our”) operates the OmniLegislation™ platform. This page describes the security measures we have in place across our infrastructure, application, data handling, and operations.


Infrastructure Security

Hosting and Deployment

The OmniLegislation™ backend and data pipeline run on cloud infrastructure hosted by DigitalOcean in the United States. The website and customer portal are hosted separately on Vercel. Our database and authentication are provided by Supabase, a managed platform built on PostgreSQL. Keeping these environments separate limits the impact of any single point of failure.

Servers run on modern, actively maintained operating systems with security patches applied regularly.

Network Security

  • All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS).
  • Communication between our application, database, and third-party service providers is encrypted in transit.
  • Access to production servers is restricted to authorized personnel through SSH key-based authentication. Password-based server access is disabled.
  • Firewall rules limit inbound traffic to only the ports and services required for the platform to operate.

Application Security

Authentication

  • Subscriber sign-in is handled by Supabase Auth, a managed authentication service. Passwords are stored using industry-standard hashing; we never see or store your password in plain text. Email sign-in links are supported as a password-free alternative.
  • Sessions use signed tokens that expire and refresh automatically, and every authenticated request to our API is verified server-side.
  • All authentication flows are transmitted over HTTPS.

Access Controls

  • Subscriber access is enforced at the application level based on your plan. For example, search coverage on single-state plans is scoped to the states included in your subscription.
  • Changes to your monitors and plan are handled through our team via the request options on your Account page, which prevents unauthorized modification of monitoring configurations.
  • Administrative access to backend systems and provider dashboards is limited to authorized personnel.

Abuse Prevention

  • Portal search results are paginated. There is no bulk listing, “show all,” or bulk export capability.
  • Access patterns are monitored for suspicious or automated behavior.
  • Accounts exhibiting patterns consistent with automated scraping or bulk data extraction may be flagged for review and suspended.

Input Validation

  • User inputs, including search queries and account settings, are validated on the server, and database access uses parameterized queries to prevent injection attacks and other common web vulnerabilities.

Data Security

Encryption

  • In Transit: All data moving between your browser, our servers, our database, and third-party services is encrypted using TLS/SSL.
  • At Rest: Database storage is encrypted at rest by our managed database provider.

Database Security

  • Our database is hosted on a managed platform (Supabase) with built-in encryption, automated backups, and access controls.
  • Database access is restricted to our application services. No direct external connections are permitted.
  • Database credentials are stored as environment variables and are never hardcoded in application code or committed to source control.
  • Automated backups are maintained by the database provider.

Payment Security

  • All payment processing is handled by Stripe, which is PCI-DSS Level 1 certified, the highest level of payment security compliance.
  • OmniLegislation™ does not store, process, or have access to full credit card numbers. All payment credentials are handled entirely within Stripe's secure environment, including card updates and cancellation through the Stripe billing portal.

AI Processing

  • Our AI relevance analysis sends the text of public legal records, together with your monitoring profile, to Anthropic (Claude models) and Voyage AI over encrypted connections. See our Data Processing Policy for details.
  • Your data is not used to train AI models under our agreements with these providers.

Email Security

  • Alert emails are delivered through Resend, an email delivery platform with sender authentication (SPF, DKIM, DMARC) and encrypted transmission.
  • Email content is generated per subscriber based on their specific Practice Area Monitors. Subscriber alert content is never shared across accounts.

Data Collection Security

  • Our data collection systems access only publicly available government sources: legislative databases, regulatory publications, and court records.
  • Collection processes include built-in rate limiting and respectful access patterns to avoid overloading source systems.
  • Collected data is validated and processed through automated deduplication and quality checks before being made available to subscribers.
  • Errors during data collection are logged and monitored. Failed collection attempts do not expose subscriber data or system credentials.

Operational Security

Team Access

  • Access to production systems, databases, and subscriber data is limited to authorized personnel on a need-to-know basis.
  • Access permissions are reviewed regularly and revoked promptly when no longer needed.

Monitoring and Incident Response

  • Platform health and error rates are monitored, and the daily data pipeline runs automated health checks that alert our team to collection failures, unusual error activity, or incomplete runs.
  • In the event of a security incident, we will investigate promptly, take steps to contain and resolve the issue, and notify affected subscribers as required by applicable law.

Dependency Management

  • Third-party libraries and dependencies are reviewed and updated to address known vulnerabilities.
  • We monitor security advisories for the frameworks and tools used in our platform.

Responsible Disclosure

If you believe you have discovered a security vulnerability in OmniLegislation™, we encourage you to report it responsibly. Please contact us at hello@omnilegislation.com with a description of the issue. We ask that you:

  • Provide sufficient detail for us to reproduce and verify the issue.
  • Allow us reasonable time to investigate and address the vulnerability before any public disclosure.
  • Do not access, modify, or delete data belonging to other subscribers during your research.

We appreciate the security research community and will acknowledge valid reports.


What We Do Not Do

To be transparent about the boundaries of our platform and practices:

  • We do not store credit card numbers or full payment credentials on our systems.
  • We do not provide public API access, webhook delivery, or bulk data export, which reduces the attack surface of the platform.
  • We do not share, sell, or trade subscriber data with third parties for purposes unrelated to operating the Service.
  • We do not access sealed, restricted, or non-public court records.
  • We do not permit our AI providers to train models on your data.

Questions

If you have questions about our security practices, contact us at:

DigitalTreehouse LLC, d/b/a OmniLegislation™

Email: hello@omnilegislation.com

Website: omnilegislation.com