Last updated: August 2026. Questions or requests: [email protected].
What NERIS authorization grants
When your department enrolls, you authorize Arborlook Insights as a read-only data exchange consumer for your department's NERIS incident records through the NERIS API, using credentials scoped to your department. That authorization lets us pull your incident records on a nightly schedule and compute the analytics you see on your dashboard.
- We never write to your NERIS records.
- We pull only your department's records, under the authorization you grant.
- You can revoke the authorization in NERIS at any time; the nightly pull simply stops.
Where your data is stored
Two systems hold your data:
- Supabase (Postgres): your organization record, user accounts, computed monthly metrics (response times, compliance, station and unit rollups), data-quality counts, and CRR activities you log.
- Cloudflare R2 (object storage): pre-computed public risk profiles, and recent-incident extracts in a private bucket that is not publicly addressable.
Raw incident pulls are processed into monthly aggregates; the dashboards you see are served from those aggregates, not from a copy of your full NERIS record set.
Encryption
All traffic between your browser and our services, and between our pipeline and NERIS, runs over TLS (HTTPS); our domains enforce HTTPS with HSTS. For questions about storage-level encryption or other platform details, contact us and we will answer specifically.
Who can access it
- Your team: access is account-based. Postgres row-level security scopes every query to your organization; members of your department see only your department's data. Regional customers see member departments' operational data only where that department has opted in to sharing.
- Arborlook: we are a small company; operational access is limited to the founder and the service credentials the pipeline runs under. We access customer data to operate the service, debug a problem you report, or as required by law.
- Nobody else: we do not sell or share your incident data. Cross-department benchmarking, when it launches, is consent-based, aggregates-only, and never names a department.
Retention
While your subscription or trial is active, we retain your NERIS-derived metrics to power your dashboard and reports. If your trial expires or you cancel, NERIS-derived data is deleted 90 days after expiration or cancellation by a scheduled purge job. Two things survive that purge, deliberately:
- Your CRR activity log, which you authored and may need for grant records; export it or ask us to delete it.
- Aggregate data-quality counts that power the free Data Quality assessment, as described in our Terms.
Free-tier risk profiles are built entirely from public data (Census, FEMA, NERIS Public) and are not subject to enrollment or retention rules.
Deletion on request
Email [email protected] from your department account and we will delete your organization's NERIS-derived data, CRR activities, and user accounts, and confirm when it is done. We do not make you wait out the 90-day clock.
Practices we hold ourselves to
- Third-party scripts and dependencies on the dashboard are version-pinned with subresource integrity hashes; our build pipeline dependencies are pinned to exact versions.
- Response-tier pages ship a strict Content-Security-Policy.
- Payment details never touch our servers; checkout and card storage are handled by Stripe.
- We publish what we measure: the methodology page documents every metric definition, and our Privacy Policy and Terms govern the rest.
We are a young company and do not yet hold formal certifications (SOC 2, ISO 27001). If your agency requires a security questionnaire or a data processing agreement, contact us; we answer those personally.