Knowledge BaseRisk Map TemplatesServices AboutStart an Engagement
Trust & Security

What PivotRisk Does With Your Data

Stated as it is today, not as it will be. Where something is still being built, this page says so.

Last reviewed September 19, 2026.

At a glance

  • No accounts or logins. There is nothing to sign in to.
  • No cookies set by the site itself, and nothing stored in your browser.
  • Form submissions are emailed to PivotRisk, not saved to a database.
  • Payment happens on Gumroad. This site never handles card details.
  • No compliance certifications yet. The program is being built in public.

Does this site use cookies?

The site's own code sets no cookies and writes nothing to your browser's local or session storage.

It is served through Cloudflare, whose security service runs a small script on every page to tell people apart from automated traffic. That service can set a security cookie of its own for that purpose. PivotRisk does not read it or use it.

Does PivotRisk use analytics?

One kind. Cloudflare Web Analytics counts page views and measures how quickly pages load. Cloudflare documents it as using no cookies or local storage and as not fingerprinting visitors. There is no advertising tracker, social media pixel, or third-party analytics script anywhere on the site.

Fonts are served from this site itself, so loading a page sends no request to Google or any other font service.

What happens to what I type into the contact or newsletter form?

The contact form asks for your name, email address, and message, and optionally your organization and a topic. The newsletter form asks only for an email address.

When you submit either one, it goes to a small program running on Cloudflare that formats it as a plain-text email and delivers it to PivotRisk's inbox through Cloudflare Email Routing. That program has no database or storage attached. It does not save your submission, and it does not write the contents to a log. It also checks that the submission came from this site and discards anything filled in by bots.

What does the Risk Intelligence Map send, and to whom?

Nothing, until you press the button to load it. After that, your browser fetches each hazard, cloud, and country feed directly from the agency or provider that publishes it. No PivotRisk server sits in between, and nothing is stored.

If you type an address to score, or drag the map pin to a spot, that location is sent to Photon, a geocoding service run by Komoot using OpenStreetMap data, so it can be matched to coordinates or a place name. It is not sent anywhere else.

How are templates sold and delivered?

Through Gumroad. Checkout, payment, and the download itself all happen on Gumroad rather than on this site, so this site never handles your card details.

How is the site secured?

It is a static site. The pages are files, with no application server or database behind them, and the only server-side code is the form handler described above. Every page is served over HTTPS, and browsers are told to require HTTPS for this domain for a year. Response headers stop browsers from guessing file types, stop other sites from framing these pages, limit the referrer information that leaves the site, and switch off access to location, microphone, and camera.

One gap, stated plainly: there is no Content Security Policy yet. The map pulls feeds from many different agencies and that list keeps growing, so a fixed allowlist in the site configuration would silently break the map the next time a feed is added. The intended home for it is the map's own code.

Does PivotRisk hold SOC 2, ISO 27001, or other certifications?

Not yet, and this page will not suggest otherwise. PivotRisk has no SOC 2 report and no ISO 27001 certificate today.

What is under way is the compliance program for the software platform PivotRisk is developing, built against GDPR, SOC 2, and the NIST Privacy Framework using PivotRisk's own templates and written up in the knowledge base as it happens. That is a roadmap, not a claim of compliance. The write-ups so far: The Trust Page Written Entirely in Future Tense and The Compliance Decisions We Made Before Writing a Line of Code.

How do I report a security issue?

Use the contact form, choose “Something else” as the topic, and say it is a security report. Include enough detail to reproduce the issue. It goes straight to PivotRisk's inbox.

What if my question is not answered here?

Ask. Security questionnaires, data handling questions, and anything this page does not cover can go through the contact form. If the honest answer is “not yet,” that is the answer you will get.

Ask a Question