Skip to content
HomePermit TrackerCounty RecordsM&A DirectoryNRA CalculatorBlog

§ Security

How we protect your data.

Last updated: July 6, 2026

1. Data Encryption

All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Database connections are encrypted, and backups are encrypted. Your deal information, owner records, and pipeline data are never transmitted or stored in the clear.

2. Payments

We do not take payments. Nothing on the site is for sale, no payment method is collected, and no payment processor is in use.

3. Infrastructure

OGLandman runs on managed cloud infrastructure with automated daily backups. Production systems are monitored with automated alerting on anomalies, and we apply security updates to our platform and dependencies.

4. Access Controls

Access to production systems is restricted to authorized personnel using multi-factor authentication and least-privilege access. Access is logged and audited.

5. Vendors and Subprocessors

We use a small set of established infrastructure providers (for hosting, database, payments, AI processing, document conversion, and email) that maintain their own security programs. We share only what each vendor needs to perform its function, under contracts that require them to protect your data. The current list is on our Subprocessors page.

6. Compliance

We follow industry-standard security practices for handling, storing, and processing data, and we conduct regular security reviews and vulnerability assessments. We do not claim a named certification we do not hold, such as SOC 2 or ISO 27001. This page describes exactly what we do. If you need specifics for a vendor or security review, contact support@oglandman.com.

7. Data Ownership

Your data is yours. We do not sell, share, or mine the email addresses the permit search and county digests collect, and we do not use them for advertising or to train AI models. Permit results can be exported to CSV at any time. Ask us to delete your address and we will, as described in our Privacy Policy.

8. Incident Response

We maintain documented incident-response procedures. In the event of a security incident affecting your data, we commit to notifying affected users within 72 hours of confirming it, and we conduct post-incident reviews to reduce the chance of recurrence.

9. Responsible Disclosure

If you discover a security vulnerability, please report it to support@oglandman.com and give us a reasonable opportunity to address it before public disclosure. We will not pursue legal action against researchers who act in good faith and avoid privacy violations, data destruction, and service disruption.

10. Security Contact

To report a vulnerability or ask a security question, contact support@oglandman.com.