Security
Security and data posture.
Reactor N operates on public-source data with a minimal-PII posture. This page summarizes our current security controls and data sources.
Hosting and infrastructure
Web hostingVercel (US edge network). TLS 1.3 for all traffic; HSTS enabled.
Data pipelinesVercel scheduled functions (serverless cron, US). Daily NRC + EIA + FERC ingest jobs.
Encryption in transitTLS 1.3 across all public surfaces and internal service-to-service traffic.
Encryption at restAES-256, managed by Vercel, on KV (key-value) and Blob object storage.
BackupsManaged, replicated durability via Vercel KV and Blob (encrypted at rest).
Access controlsNo persistent servers (serverless architecture); platform access governed by Vercel account controls.
Data we collect
- Public data only for the pricing index, restart tracker, and deal ledger. Sources: NRC ADAMS, EIA-923, FERC OASIS, FERC filings, SEC EDGAR, state PUC filings, public IR transcripts.
- Email addresses, only where someone opts in to a newsletter or research alert. No additional PII collected.
- Product usage metrics in aggregate (page views, total API request counts). No third-party trackers on any Reactor N page.
- No data from your own systems. We do not ingest, store, or process operational, business, or telemetry data from anyone's systems. Reactor N runs entirely on the public record.
Data we publish
- NPPI ($/MWh) — derived from primary-source filings. Methodology fully documented.
- Deal ledger — every entry has source citations. No private or NDA-protected information.
- Restart and pipeline tracker — public agency filings and corporate press releases only.
If you believe any published item misrepresents non-public information, contact hello@reactorn.com with details. We respond within one business day.
Compliance
GDPRLiveData minimization, lawful basis (consent), data subject rights honored.
CCPA / CPRALiveRight-to-know and delete honored. No sale of personal data; no targeted advertising.
Vulnerability reporting
Found a security issue? Email security@reactorn.com (PGP key available on request). We acknowledge within 24 hours and provide a remediation timeline within 5 business days. No bug bounty at present, but we recognize responsible disclosures in our security acknowledgments page (forthcoming).
Subprocessors
- Vercel Inc. (USA) — web hosting, serverless backend, data pipelines, KV + Blob storage
- Google Cloud DNS — authoritative DNS for reactorn.com
- Groq, Inc. (USA) — AI inference for in-product assistants