Skip to main content
RecallStream
How it worksSourcesAPIPricingFAQAboutContact
Sign inStart free →
How it worksSourcesAPIPricingFAQAboutContact
Sign inStart free →

Security & Compliance

Last updated: June 23, 2026

RecallStream is built and operated with security in mind. This page summarises our approach to keeping your data safe. Technical and organisational measures are detailed in Schedule 1 of our Data Processing Agreement.

Encryption & Hashing

TLS 1.2+ in transit · Argon2-hashed passwords · One-way-hashed API keys · AES-256-GCM-encrypted webhook secrets

Least-Privilege Access

Operator-only production access via SSH keys · Centralised logs · Role-based permissions · No shared credentials

GDPR / CCPA Ready

Transparent policies · User rights honoured · DPA on request · No data sold

All data in transit between your browser or API client and RecallStream's servers is encrypted using TLS 1.2 or higher. We enforce HTTPS and use HTTP Strict Transport Security (HSTS) to prevent protocol downgrade attacks.

Customer data is stored on EU (Germany) infrastructure with access restricted to the operator; database backups are stored in access-controlled EU object storage with a 30-day lifecycle. API keys (rr_…) are stored as one-way hashes — we cannot read them back; webhook signing secrets (whsec_…) are encrypted (AES-256-GCM) at the application layer. Neither is ever logged in plaintext. When you rotate or revoke a key, the old value is immediately invalidated and cannot be recovered.

RecallStream is hosted on Hetzner cloud infrastructure in the European Union. All customer data is stored in EU data centres. We use private networking between services — no sensitive data travels over the public internet between internal components.

Daily database backups are stored in access-controlled EU object storage (Hetzner Object Storage, Germany), separate from the primary server. Backups expire automatically after 30 days, so residual copies of deleted data are purged within 35 days at the latest.

We follow a secure software development lifecycle (SSDLC). All code changes are reviewed and must pass an automated CI pipeline — type checks, linting, and the test suite — before release.

We apply standard security headers on all responses: HTTP Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy. All user inputs are validated and parameterised queries are used throughout to prevent SQL injection. API endpoints are rate-limited to prevent abuse and brute-force attacks.

User passwords are hashed using Argon2 and are never stored in plaintext. Sessions expire after a period of inactivity and are invalidated on sign-out.

Production access is limited to the operator, authenticated with SSH keys; there is no shared or standing third-party access. Application and infrastructure logs are centralised (Grafana/Loki).

RecallStream operates centralised log collection (Grafana/Loki). Security-relevant events — authentication attempts, API key usage, permission changes, and administrative actions — are logged and retained for analysis. Full API keys and webhook secrets are never written to logs.

RecallStream maintains a documented Security Incident Response Plan. In the event of a confirmed security breach involving personal data, we will notify affected customers without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required under GDPR Article 33.

We operate a responsible disclosure policy. If you discover a security vulnerability in RecallStream, please report it to security@recallstream.com before public disclosure. We will acknowledge your report within 5 business days, keep you informed of our progress, and credit you for the discovery (unless you prefer to remain anonymous). Please do not test against production accounts or data belonging to other users.

RecallStream operates in compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and the Ukrainian Law on Personal Data Protection. Our privacy practices are detailed in our Privacy Policy and our Data Processing Agreement.

We do not sell personal data. We do not use your watchlist or recall event data to train machine learning models. Our analytics are cookieless and identifier-free; the cookie banner additionally offers an analytics opt-out. You have the right to export and delete your data at any time via Settings → Privacy → Manage my data.

Before engaging a new subprocessor, we assess their security posture, privacy practices, and compliance certifications. Each subprocessor signs a Data Processing Agreement committing to data protection standards at least as protective as our own. The current subprocessor list is published in DPA — Schedule 2. We notify customers before adding new subprocessors and accept objections on reasonable data-protection grounds.

Security is a shared responsibility. To protect your account:

  • Use a strong, unique password for your RecallStream account.
  • Protect your API key (rr_…). Treat it like a password. Do not commit it to source control, expose it in client-side code, or share it with people who do not need it. If it is exposed, rotate it immediately from Settings → API Keys.
  • Protect your webhook signing secret (whsec_…). Verify the HMAC-SHA256 signature on every incoming webhook event before processing it. If your signing secret is compromised, rotate it immediately from Settings → Webhooks. The old secret is invalidated as soon as you rotate.
  • Review your API keys regularly and revoke any you no longer use. Signing out revokes your session tokens.
  • Never log your full API key or webhook secret — in application logs, error tracking systems, or any other observability tool.
Incident? If you believe your API key or webhook secret has been compromised, rotate it immediately and then contact security@recallstream.com to investigate whether any unauthorised access occurred.

For security disclosures, vulnerability reports, or questions about our security practices:

  • Security email: security@recallstream.com
  • Privacy / DPA enquiries: privacy@recallstream.com
  • Post: Sole Proprietor (FOP) Kharchenko Yaroslav Oleksandrovych, Komunalna St 16, Hlukhiv, Sumy Oblast, 41400, Ukraine
RecallStream

Cross-agency product-recall intelligence — normalized, near-real-time, developer-friendly.

Sole Proprietor (FOP) Kharchenko Yaroslav Oleksandrovych
Komunalna St 16, Hlukhiv, Sumy Oblast, 41400, Ukraine

Product

  • Pricing
  • API Docs
  • FAQ

Sources

  • openFDA
  • CPSC
  • NHTSA
  • EU Safety Gate
  • FSIS (coming soon)

Company

  • About
  • Contact
  • Security

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy
  • Data Sources & Licensing
  • Acceptable Use
  • Do Not Sell / Share
  • Accessibility
  • DPA Overview

© 2026 RecallStream