Security

Our practices.

How Ghost handles your data, end-to-end.

Ghost handles the most sensitive personal data many people own. Our practices reflect that. This page is the operational view of how we keep your data safe and how we make sure that the work we do on your behalf actually gets done. The contractual version of these commitments lives in our Data Processing Agreement and Privacy Policy.

Encryption

All traffic to and from Ghost is encrypted in transit with TLS 1.3. All persistent storage — primary databases, object storage, search indices, and message queues — is encrypted at rest with AES-256-GCM. Keys are managed in AWS KMS with rotation every 90 days. Backups inherit the same encryption envelope and are stored in a separate AWS account with cross-account access controls. Disk-level encryption is in addition to, not instead of, application-level envelope encryption of the most sensitive identifiers.

Access

Production access requires a hardware security key (FIDO2/WebAuthn), a fresh just-in-time approval from a second engineer, and a short, scope-bound session. Standing access is treated as an incident. Every access event — query, command, secret retrieval — is logged to an append-only audit trail in a separate account that the engineer triggering the event cannot modify. Internal SSO, device-trust posture (managed devices, latest OS, full-disk encryption), and DLP rules apply to every staff endpoint.

Data minimisation

We only collect what we need to find your exposed data and remove it. Identifiers you enter are pseudonymised before they reach our scanner workers; the lookup tables are kept in a separate database with tighter access controls. We do not enrich your account with third-party data brokers or marketing databases. We never sell, rent, or share your information with advertisers, and we never use your data to train any model — ours or anyone else's.

How removals actually happen

A removal is a piece of work, not a button. For every exposure we find, we identify the broker, the legal regime that applies to you (CCPA, CPRA, GDPR Article 17, UK GDPR, PIPEDA, broker-specific opt-out forms), and the channel that broker actually responds to — which is rarely the one on their public site. We submit, capture a timestamped proof of submission, and chase. If the broker re-publishes your data later, we reopen the case automatically. Average first removal: under seven days. Long tail of stubborn brokers: 30 to 90 days. Removals that involve specialist legal work (court records, ranking suppression in search results, dark-web takedowns) are handled by a Ghost analyst with subject-matter experience and a named lawyer in the loop.

Monitoring and re-scanning

Brokers re-publish. Search results re-index. Breaches keep being traded. Our default is to re-scan weekly on Premium and monthly on Intelligence — but the scanner schedule is also driven by risk signals: a new breach landing, a broker known to recycle data, a new identifier you have added, or a regulator enforcement action that opens a previously closed channel. Every re-scan produces a diff: what is new, what is back, what is still gone.

Incident response

We follow a documented incident-response plan that maps to ISO 27035 and the NIST SP 800-61 lifecycle. Severity-one incidents page on-call within minutes, kick off a war room, and trigger regulator-clock obligations on the same call. Customers affected by a personal-data breach are notified without undue delay and within 48 hours of confirmation, with the content required to support your own regulator notifications. We publish a quarterly transparency report covering incidents and government requests.

Compliance and certifications

  • SOC 2 Type II — audited annually by an independent firm. The latest report is available under NDA from security@useghost.me.
  • ISO 27001 — certified, with a documented statement of applicability and an information-security management system reviewed at least annually.
  • GDPR / UK GDPR / Swiss FADP — full compliance posture documented in our GDPR page, Privacy Policy, and DPA.
  • CCPA / CPRA — California residents' rights and our Do-Not-Sell / Do-Not-Share posture are documented in our Privacy Policy.
  • Penetration testing — quarterly internal, annual external from a CREST-certified firm. Redacted executive summaries are available under NDA.
  • Bug bounty — coordinated disclosure programme run with HackerOne; safe-harbour terms in our security.txt.

Vendor and sub-processor review

Every sub-processor goes through a documented intake review covering security, data residency, contractual safeguards, and business continuity. We re-review existing sub-processors annually and on any material change in their posture. Our current sub-processor list, the categories of data each one processes, and the country of processing are maintained in Annex III of our DPA; we notify customers at least 30 days before adding any sub-processor that handles identified personal data.

Business continuity

Ghost runs on a multi-region architecture with automated failover within the EU (primary: Frankfurt; secondary: Dublin) and within the US (primary: Northern Virginia; secondary: Oregon) for US customers. RPO is under 15 minutes and RTO under one hour for regional failure. Backups are encrypted, isolated, and exercised quarterly with a documented restore drill.

Responsible disclosure

If you find a security issue, write to security@useghost.me. We acknowledge within one business day, triage within five, and will not pursue legal action against good-faith researchers who follow our coordinated disclosure terms.