Security
Security and data posture.
Reactor N operates on public-source data with a minimal-PII posture. This page summarizes our current security controls, data sources, and compliance roadmap. Enterprise prospects can request a pre-filled SIG-lite vendor questionnaire.
Hosting and infrastructure
Web hostingVercel (US edge network). TLS 1.3 for all traffic; HSTS enabled.
Data pipelinesVercel scheduled functions (serverless cron, US). Daily NRC + EIA + FERC ingest jobs.
Encryption in transitTLS 1.3 across all public surfaces and internal service-to-service traffic.
Encryption at restAES-256, managed by Vercel, on KV (key-value) and Blob object storage.
BackupsManaged, replicated durability via Vercel KV and Blob (encrypted at rest).
Access controlsNo persistent servers (serverless architecture); platform access governed by Vercel account controls. Role-based access controls (RBAC) for application surfaces.
Data we collect
- Public data only for the pricing index, restart tracker, and deal ledger. Sources: NRC ADAMS, EIA-923, FERC OASIS, FERC filings, SEC EDGAR, state PUC filings, public IR transcripts.
- Named-user emails for authentication and product access. No additional PII collected.
- Product usage metrics in aggregate (page views, API calls per key). No third-party trackers on customer dashboards.
- No customer-business data. We do not ingest, store, or process any data from customers' own systems unless explicitly contracted for a custom integration.
Data we publish
- NPPI ($/MWh) — derived from primary-source filings. Methodology fully documented.
- Deal ledger — every entry has source citations. No private or NDA-protected information.
- Restart and pipeline tracker — public agency filings and corporate press releases only.
If you believe any published item misrepresents non-public information, contact hello@reactorn.com with details. We respond within one business day.
Compliance
GDPRLiveData minimization, lawful basis (contract/consent), data subject rights honored.
CCPA / CPRALiveRight-to-know and delete honored. No sale of personal data; no targeted advertising.
SOC 2 Type IIQ4 2026Audit scoping in progress. Pre-audit gap analysis completed.
ISO 270012027Planning phase. Sequenced after SOC 2.
NIST 800-171On requestFor enterprise customers in regulated industries. Available via custom DPA.
SIG-lite questionnaireLivePre-filled. Available on request for enterprise prospects.
Vulnerability reporting
Found a security issue? Email security@reactorn.com (PGP key available on request). We acknowledge within 24 hours and provide a remediation timeline within 5 business days. No bug bounty at present, but we recognize responsible disclosures in our security acknowledgments page (forthcoming).
Subprocessors
- Vercel Inc. (USA) — web hosting, serverless backend, data pipelines, KV + Blob storage
- Google Cloud DNS — authoritative DNS for reactorn.com
- Anthropic PBC (USA) — AI inference for in-product assistants
- Stripe Inc. — payment processing (when applicable to subscription)
Document requests
Enterprise prospects can request the following before signature:
- SIG-lite pre-filled vendor questionnaire
- Data processing agreement (DPA) draft
- Subprocessor list with current contracts
- Penetration test summary (most recent)
- Incident response plan summary
Email hello@reactorn.com with your specific request.