Turn your existing user base into a recurring privacy business
Launch a fully branded personal data exposure and removal product in weeks, not months. We provide the infrastructure. You own the customer, the brand and the recurring revenue. White-label data removal and exposure scanning, delivered as an API: your platform submits a person, we search the high-authority US people-search sites, return the listings with profile URLs and a confidence rating on each, score the risk, and submit the opt-out requests. You render the result as your own product.
Three steps, and none of them are yours to build
1. Your platform calls the APIwith a person's details and your proxy credentials.
2. We do the work. Discovery across supported sources, evidence capture, risk scoring, submitting removal requests, and handling the confirmation and identity-verification exchange with each broker — so a request that a broker will only process after an identity check still completes.
3. You get structured JSON back, by signed webhook or polling. No branding, nothing that reveals a supplier.
User subscribes on your platform
|
Your backend calls the API
|
Exposure report returned
|
Removal requests submitted
|
User sees your branded report
|
Monthly re-scan, on your scheduleYou control cadence. Scan on signup, on a schedule, or when a user clicks refresh. Whether you market that as continuous monitoring is your product decision, using your own scheduler and your own customer data.
A product ladder your users climb
The same integration gives you three things to sell, each a natural upsell from the last. Start with the assessment; the recurring revenue is in the layers above it.
A one-time scan: the sites a person is listed on, the profile URLs, the exact data categories, and a confidence rating on each. The low-friction entry point — an assessment your team can run to show a prospect their exposure and win the sale.
Recurring scans that return a change ledger, not just a fresh list: what appeared, what a broker republished, what is still listed, what could not be verified. The history is what makes it a subscription — it proves the work is ongoing.
Statutory opt-out filing as an authorised agent, the broker confirmation and identity-verification exchange, California DROP and the state mechanisms that follow, each with a durable audit record. The premium tier, layered on once your users are subscribed.
You can launch on the assessment alone and add the layers as your users ask for them. You are not signing up to ship all three on day one.
- Launch in weeks instead of months. The hard parts are already solved.
- No dedicated engineering team to build or maintain the discovery layer.
- No maintenance burden as sources change. That cost is ours.
- White-label from day one. Nothing in the response names a supplier.
- Usage-based commercial model. Cost scales with adoption, not headcount.
- Direct access to the people building it, rather than a support queue.
Built for recurring revenue
Privacy is not a one-time purchase. People-search sites continuously republish personal information, which is why every successful privacy product is a subscription business rather than a single transaction.
That recurring characteristic is what makes this attractive to a platform that already has an audience. Acquiring a privacy customer from scratch is expensive. Adding a privacy product to users you already have is not.
Who this is for
- • VPN and consumer privacy suites
- • Identity verification and KYC providers
- • Password managers and security apps
- • Credit monitoring and identity-theft protection
- • Managed security providers offering executive protection
If you already own the customer relationship, you own the hard part. Engineering is what stops most platforms shipping this.
What your users see
The actual listings, with proof. The sites a person appears on, the profile URL where they appear, and the exact data categories exposed there: address, phone, email, relatives, court records. Not a count. Evidence.
A confidence rating on every listing. Each result is rated strong, moderate or weak based on how many of the subject's own identifiers were confirmed on the page. Showing a user a same-name stranger's record is the failure that destroys trust in a privacy product. Here it is measured, not assumed.
A risk score they understand. A 0-100 score plus named threat scenarios (doxxing, physical location, social engineering, identity fraud, family targeting), each derived from the specific combination of data found.
A prioritised plan. Listings ranked by risk reduction per unit of effort, so the first action taken is the one that matters most.
Honest reporting of what could not be checked. Sources that block the scan are returned explicitly as unverified, never quietly counted as clean.
- OpenAPI 3.1 contract — normative, so your team generates a client rather than hand-writing one
- Versioned API — with 30 days notice on any breaking change
- Asynchronous job model — so long-running work never blocks your request path
- Signed webhooks — with replay protection, so your platform can trust every callback
- Per-customer signing secrets — rotatable on request
- Encryption at rest — for all sensitive customer data
- API keys never stored — in recoverable form
- Durable audit record — for every removal submission, producible if challenged
- Correct legal basis per subject — each request cites the privacy law and rights of the subject's own state of residence, not a one-size-fits-all template
- Processor-only data handling — you hold the customer relationship, the consent and the data-subject obligations
Status today
- Exposure scanning: available now
- Evaluation environment: live, credentials issued on request
- OpenAPI 3.1 specification: published
- Signed webhook delivery: supported
- Automated removal:live. Statutory opt-out requests are filed as an authorised agent under the correct state privacy law for each subject, the confirmation and identity-verification exchange with the broker is handled — so a request a broker will only process after an identity check still completes rather than stalling — and every submission carries a durable audit record. Sending volume is ramped deliberately rather than run flat out, because deliverability is what makes a request land at all.
- Removal progress webhooks: supported. Status changes are pushed per broker as they happen, so your UI is never guessing between submission and outcome.
- Re-listing monitoring:live. Removed listings are re-checked on a schedule and re-filed automatically when a broker republishes, so "removed" is a state that is held rather than a snapshot taken once.
- California DROP:ready. The deletion mechanism is modelled as a first-class channel, so as California's platform becomes enforceable it takes precedence over per-broker filing for eligible subjects without any change on your side.
- Source coverage: an ongoing programme, expanding continuously
Why not build it yourself
| Building in-house | Using this API |
|---|---|
| Months of engineering before any revenue | Integration in days |
| A permanent team tracking source changes | Maintenance is our cost |
| Continuous protection changes to keep up with | Already handled |
| Removal audit trail built from scratch | Included by design |
| Fixed cost regardless of adoption | Cost scales with usage |
Every month spent building this internally is a month the subscription revenue does not exist.
Pricing
One subject. One API call. One price. Everything required to process them is included: discovery, the removal requests raised against what is found, and the report.
No tiers to model, no platform fee, no per-source rates to reconcile. A person listed on twelve sites costs the same as a person listed on two, because the variable work is ours to absorb rather than yours to forecast.
Pricing is simple, usage-based and designed for partner integrations. Contact us to discuss expected volume and receive a commercial proposal.
Contact us for pricingFrequently asked questions
Can we white-label this completely?
Yes. The API returns structured JSON with no branding of any kind. Your users never see a supplier name. You control the interface, the pricing and the customer relationship entirely, and the response contains nothing that identifies where the data came from.
How long does integration take?
Typically two to five days of engineering. The API is documented with a normative OpenAPI 3.1 contract, so your team can generate a client directly rather than hand-writing one. The job model is asynchronous: you submit a scan and receive a signed webhook on completion, or poll for status.
Can you guarantee a listing gets removed?
No, and neither can anyone else. Whether a data broker honours an opt-out request, and how quickly, is outside any provider's control. What is guaranteed is that the request is executed properly, that the confirmation and identity-verification exchange with the broker is handled — including when a broker will only act after an identity check, such as confirming a postal address — and that every submission is evidenced with a durable audit record so it can be produced if challenged. You are buying execution, not a promise made on a broker's behalf.
Which sources do you cover?
The high-authority US people-search tier: the sites that actually surface when someone searches a person's name, which is where real exposure comes from. The live list is available from the API itself, so your integration always sees the current set rather than depending on a list in a document. Coverage expands continuously.
Do we need our own proxies?
Yes. You supply residential proxy credentials per call. That bandwidth is your cost and carries no markup from us. Your credentials are used for that call only and are never stored.
What happens if a source blocks the scan?
That source is returned explicitly as unverified, with the reason, rather than being reported as clean. Telling a user they are not listed somewhere that could not actually be reached is a false negative, and in a privacy product that is the damaging direction to be wrong in. We would rather tell you what could not be checked.
Who owns the customer data?
You do. We act solely as your processor, working on your documented instructions. You hold the consumer relationship, the consent, and responsibility for data-subject requests. Sensitive data is encrypted at rest and per-call proxy credentials are never persisted.
How long does a scan take?
Typically two to three minutes, with the large majority finishing inside six. Scans run asynchronously so nothing blocks your request path: submit a job, then receive a signed webhook on completion or poll for status. A repeat scan for the same person inside the cache window returns immediately and is not billed again.
How do we keep up with changes?
The documentation and the source list are endpoints, not attachments. Both are served from the API and versioned, so your integration reads the current state rather than a document that was accurate when it was emailed. Material changes are announced on a webhook, and breaking changes carry 30 days notice.
Is this suitable for executive protection?
Yes. Risk scoring supports an executive profile that weights home address, family connections and property records more heavily than a standard consumer profile, which is usually the relevant threat model when protecting a named individual.
Add a privacy product to your platform
You already have the users, the brand and the distribution. We provide the infrastructure so you can focus on your product.
Request evaluation access