Last updated: April 2026

Platform Security

How OilFlow protects your data, your deals, and your compliance posture.

Standards & Certifications

SOC 2 Type II

Not started

Auditor shortlist prepared; engagement deferred until a customer's procurement requires it

CSA CAIQ v4

Self-attested

Published responses available on request to procurement teams

PCI DSS Level 1

Via Stripe

OilFlow never stores or processes card data

GDPR

Compliant

DPA published at /dpa; SCCs available for EU transfers

CCPA

Compliant

California privacy rights

Kenya DPA 2019

Compliant

East Africa operations

AML / KYC

Enforced

7-step verification pipeline

OFAC / UN / EU / UK / CA / AU / CH

Active screening

8 publisher lists, each converted from the publisher's own file and served from OilFlow's own index

Posture · self-attested with audit roadmap

  • SOC 2 Type II: not started. An auditor shortlist and a draft engagement letter exist; no auditor is engaged, no letter is signed, and no gap analysis has been performed. The engagement is deferred until a customer’s procurement requires it. We will publish the observation-window and report dates once a letter is signed, not before.
  • Third-party penetration test: not scheduled. No testing firm is engaged and no letter of engagement exists.
  • Cyber liability insurance: in procurement for $5M / $10M aggregate. Certificate of insurance will be furnished to enterprise customers at contract execution.
  • Bug bounty: coordinated vulnerability disclosure at [email protected] with 90-day disclosure window. Formal HackerOne program scoped for post-Series-A.

Procurement deeper dive: see sub-processors, DPA, and the CSA CAIQ v4 response (request via [email protected]).

Infrastructure

Single database, single location — hosted on Supabase (AWS), which holds independent SOC 2 Type II certification

PGP symmetric encryption on sensitive fields (email, payment IDs, beneficial owners)

TLS 1.2+ on every connection — HSTS enforced with 1-year policy

Stateless application layer — processes requests, stores nothing

Row-level security — database-enforced access isolation per member

Browser→ TLS →App (stateless)→ TLS →Database (encrypted)

Access Control

Row-level security policies on all database tables

Server-side session verification on every request

Deal room isolation — party membership verified before access

Append-only audit trail with operator ID and timestamp

Security headers: CSP, X-Frame-Options DENY, HSTS, strict-origin referrer

Verification Pipeline

Every member passes all 7 steps. No exceptions.

1
Sanctions Screening8 source lists (OFAC SDN, OFAC Consolidated, UN, EU, UK HMT, Canada SEMA, Australia DFAT, Switzerland SECO). Any match = automatic rejection. Non-overridable.
2
Company RegistrationLegal entity confirmed via country-specific registries (SECP, DMCC, EPRA, etc.).
3
Regulatory LicenseCountry-specific petroleum licenses verified (OGRA, EPRA, EWURA, etc.).
4
Asset ConfirmationPhysical assets verified through independent sources.
5
Trade ReferencesTwo independent references contacted and verified.
6
Digital FootprintWebsite, LinkedIn, and news presence evaluated.
7
Scam ScreeningLOI/ICPO/DLC MT700 pattern detection. Blocklist matching.

Re-screened every 90 days. Any new flag triggers immediate suspension.

Data Handling & AI

Zero retention by AI provider — processed in memory, then discarded

Never used for model training — contractual guarantee via API terms

We share (when required)

Company name with matched counterparties — after both verified
Names with sanctions screening — legal requirement
Billing info with Stripe — PCI DSS Level 1
Anonymized trade specs with AI — no identifiers

We never

Sell or license your data
Share data with competitors
Let AI train on your data
Trade against your deal information
Reveal company details before you confirm interest

Third-Party Processors

ServicePurposeCompliance
SupabaseDatabase & authSOC 2 Type II
StripePaymentsPCI DSS Level 1
AnthropicAI servicesZero retention; Claude for Startups (2026)
ResendTransactional emailDPA available

Zero advertising cookies. Zero tracking pixels. Zero analytics scripts.

Incident Response

72-hour breach notification

Per GDPR Article 33. Affected members notified within 72 hours of confirmed breach.

Responsible disclosure

Report vulnerabilities to [email protected]

Review cadence

Internal security reviews conducted as needed.

Your Controls

Export Your Data

Download everything we hold about you as a structured file.

Download →

Delete Your Account

Removed within 24 hours. Compliance records retained per law.

[email protected]

Data Access Log

See every access — which system, what purpose, when.

View log →