Last Updated: July 2026
Ginzamarkets, Inc.
659 N. High Street, Suite 250
Columbus, Ohio 43085 USA
DemandSphere is an enterprise search intelligence platform. This page describes the technical and organizational measures we use to protect customer data. It reflects our practices as of the date above and is reviewed as those practices change.
Infrastructure
Hosting. DemandSphere runs on dedicated infrastructure that we administer directly, hosted in physically secure data centers in the European Union and the United States. Our infrastructure providers are Hetzner, OVH, and Backblaze. We do not run on shared platform-as-a-service infrastructure, and we control the operating system, database, and application layers ourselves.
Physical security. Data center physical security is the responsibility of our infrastructure providers and is covered by their published certifications and attestations. Controls include restricted personnel access, access review, 24/7 monitoring, CCTV coverage of physical access points, and electronic intrusion detection. Environmental controls include climate management, automatic fire detection and suppression, and water leak detection.
Availability and redundancy. Production databases are configured with primary and secondary replication where feasible. Data is backed up to durable storage, encrypted, and replicated across geographically separate locations. Our infrastructure providers target a minimum of 99.9% availability. This is a design target rather than a contractual service level; contractual availability commitments, where applicable, are set out in the agreement with the customer.
Data protection
Encryption. Data is encrypted in transit using TLS 1.2 or higher across the platform and all public interfaces. Data at rest is encrypted using AES-256.
Tenant isolation. Customer data is logically segregated by tenant. Tenant scoping is enforced in the application and data layers. Customers access data through the application interface and API only; direct access to underlying infrastructure is not provided. Authorization is validated per request against the user's assigned permissions.
Access to customer data. Access to production systems and customer data is limited to a small number of personnel on a role-based, need-to-know basis, for the purposes of support, troubleshooting, and incident response. Internal access requires SSO with two-factor authentication, and access to internal resources is mediated through VPN.
AI features and customer data. AI-assisted features operate on publicly available search and web data to generate analysis and recommendations. Customer data is not sent to a model provider without your permission. AI features are optional and are not enabled by default. Model providers are listed on our Approved Sub-Processors page, and provider agreements prohibit the use of customer data to train their models. Use of AI-assisted features is also subject to our Content Policy.
Retention and deletion. Customer personal data is deleted when no longer necessary for the purposes for which it was collected, subject to retention required by law or present in routine backup cycles. Deletion and return obligations on termination are set out in our Data Processing Addendum.
Application security
Development lifecycle. Changes are peer reviewed, tested, and logged before deployment to production. Our change management process is designed to reduce the likelihood of unauthorized or unreviewed changes reaching production. Developers work to OWASP secure coding practices.
Environments. Staging, testing, and development environments are logically separated from production and from one another. Access to non-production environments is restricted to authorized personnel and subject to the same authentication and access controls as production.
Security testing. We conduct internal penetration testing annually. Code in our repositories is reviewed for security-relevant defects as part of standard review. We monitor for security vulnerabilities in our dependencies and infrastructure and apply patches and configuration changes on an ongoing basis.
Network controls. Network access controls are designed to prevent traffic using unauthorized protocols from reaching platform infrastructure. Measures include private network segmentation, security group assignment, and firewall rules. Internet-facing applications sit behind a web application firewall.
Authentication options for customers. We support single sign-on via OIDC with Google, Microsoft, and Okta. Additional providers can be considered for enterprise deployments. Two-factor authentication is currently available on Enterprise plans and is being extended to all plans.
Monitoring and incident response
Logging and monitoring. Infrastructure and application activity is logged, aggregated, and forwarded to a SIEM. Alerting is configured on security-relevant events. Access to logs and audit trails is restricted to authorized personnel.
Incident response. We maintain a record of known security incidents including description, timeline, and disposition. Suspected and confirmed incidents are investigated, and resolution steps are identified and documented. Where we become aware of unlawful access to customer data, we notify affected customers, describe the steps being taken, and provide status updates through resolution. Notification obligations for personal data breaches are set out in our Data Processing Addendum.
Reporting a vulnerability. Security researchers and customers can report suspected vulnerabilities to [email protected]. We acknowledge reports and work with reporters through remediation.
Organizational security
Workforce. DemandSphere operates as a distributed company, with personnel in the United States, Japan, Pakistan, and Poland working primarily remotely. Our Columbus, Ohio location is a managed shared workspace. Because our workforce is distributed, our security model is built around identity, device, and network controls rather than physical office perimeter.
Personnel. Employees and contractors sign confidentiality agreements before beginning work. Personnel with access to production systems are subject to role-based authorization and are removed on separation.
Security awareness. All personnel receive security awareness training at onboarding and periodically thereafter, covering phishing, credential handling, data classification, and incident reporting.
Security ownership. Information security is owned by our Head of Infrastructure, who is responsible for infrastructure security, monitoring, and incident response, reporting to the Chief Executive Officer.
Risk management. We maintain a risk management process to identify, evaluate, and treat information security risks. Risk assessments are performed at least annually and when a material change occurs in our technology, organization, or regulatory environment.
Vendors and sub-processors
We assess third-party vendors for security and data handling before onboarding, and we maintain contractual protections covering data processed on our behalf. Our current sub-processors are published at https://www.demandsphere.com/approved-sub-processors-and-joint-controllers/ and customers are notified of changes in accordance with our Data Processing Addendum.
Privacy and compliance
We process personal data in accordance with applicable data protection law, including the GDPR, the UK GDPR, and the CCPA. Our practices include collecting the minimum data necessary to provide the service, maintaining a published sub-processor list, entering data processing addenda with customers and vendors, and maintaining a public privacy policy describing our data collection practices.
We are currently pursuing a SOC 2 Type II attestation, with our observation window opening in early 2027. We use Vanta for continuous control monitoring and evidence collection in support of that program.
Related documents: Privacy Policy, Data Processing Addendum, Sub-Processors, Terms of Service.