Trust
Trust & security
Where our data comes from, where yours is held, and what we do and don’t hold by way of certification. Written to answer a procurement checklist without you having to send one.
Legible holds information about other people’s companies, and asks you to trust us with information about yours. This page sets out how that works in practice. Where the honest answer is “we don’t have that yet”, it says so — section 8 in particular.
1. Who we are
Legible is built and operated by Glint Limited, a New Zealand registered company, trading as Legible. We are New Zealand owned, and the service is governed by New Zealand law.
| Legal entity | Glint Limited, trading as Legible™ |
| Registered office | 26 Waima Crescent, Titirangi, Auckland 0604, New Zealand |
| Governing law | New Zealand |
| Privacy and security contact | privacy@legible.nz |
2. Where our data comes from
Legible does not scrape. Every register we draw on is accessed either under a written agreement with the relevant authority or from an official public feed.
Under agreement with the Ministry of Business, Innovation and Employment (MBIE) and the Companies Office, on a signed API Access Agreement with approved subscriptions to each:
- the NZBN and Companies Register;
- the Companies Entity Role Search (directors, shareholders and other officeholders);
- the Companies Disqualified Director Search;
- the Personal Property Securities Register (PPSR), which additionally required a Companies Office customer account and direct-debit authority;
- the Insolvency Register;
- the Companies Office bulk register extract, under a separate Bulk Data Access Agreement.
From official public feeds, which require no subscription: the New Zealand Gazette, WorkSafe enforcement notices, GETS procurement notices, the MFAT Russia Sanctions Register, and the Charities Register.
Two things follow from that. First, we are a licensed consumer of official register data rather than a re-publisher of scraped data — we do not resell or redistribute the raw datasets, and what you pay for is the analytical and interface layer built on top of them. Second, our access carries obligations that flow through to you: our agreements require that people using the data downstream are bound by equivalent terms, which is why accepting our Terms of service is a condition of holding an account and is captured when you first sign in.
3. Accuracy and uncertainty
Register data records what was filed. It is not a verified statement of fact, and it is only ever as current as its source. We treat that as a design constraint rather than something to disclaim in the small print:
- Every view built on register data shows the date the data is as at, with a refresh option wherever a live lookup is available.
- Where we have matched records across registers by name rather than by company number or NZBN, we say so and we grade our confidence in the match. A probable match is never presented as a certain one.
- We do not produce credit scores, or risk ratings presented as fact, and we do not give financial advice. Where we surface a signal, we show the basis for it so you can form your own view.
4. Hosting and data location
| Application and database | Netcup GmbH — Germany (EU) |
| Authentication | Self-hosted Keycloak on the same infrastructure — no third-party identity provider |
| Off-site backups | Hetzner Online GmbH — Germany (EU), encrypted by us before transfer |
| Transactional email | Resend, Inc. — United States |
| Payments | Stripe — Stripe New Zealand Limited; Stripe Payments Europe, Limited (Ireland) |
Your data is hosted in the European Union, not in New Zealand. We would rather state that plainly than have you find it in a security review. Germany, as an EU member state, operates under the GDPR, which provides privacy safeguards comparable to — and in some respects more stringent than — those required by the Privacy Act 2020, and our hosting and backup providers are engaged under GDPR Article 28 data processing agreements confirming they process our data only to deliver their service to us. That is the basis on which we rely for overseas storage under Information Privacy Principle 12. Full detail, including email and billing, is in section 8 of our Privacy statement.
Customers cannot currently choose a data region.
5. Security
Authentication. Sign-in runs through a self-hosted Keycloak instance rather than a third-party identity provider. The application itself never stores your password.
Internal access. Access to customer data is limited to the operator of the service, for support, incident response and billing correction. There is no broad internal support team with standing access to the contents of your account.
In transit. All traffic to legible.nz, app.legible.nz and our authentication service is served over HTTPS/TLS, with certificates renewed automatically.
Separation. Your data is scoped to your organisation. Watchlists, lists, notes and generated reports are visible to members of your organisation and to no other Legible customer.
Audit trails. We keep internal audit records of account changes, report generation and scheduled data jobs — for billing accuracy, for security investigation, and to meet our own obligation to respond to MBIE audit requests.
Payment details. We never see or store your card details. Card data is handled entirely by Stripe.
6. Backups and recovery
Backups run nightly, in three layers, because the three things that can go wrong fail differently:
| Layer | What it protects against | Where it lives |
|---|---|---|
| Nightly database dumps | A bad migration, an accidental deletion, or a request for a single table as it was last Tuesday | On the server, and inside every off-site archive |
| Encrypted off-site archive | Loss of the whole machine — fire, compromise, account closure | Hetzner Storage Box, Germany (EU). Retained 7 daily, 4 weekly, 6 monthly |
| Whole-disk snapshots | Needing to roll the entire machine back quickly | Netcup, Germany (EU) |
Both the application database and the authentication database are backed up. Archives are encrypted by us before they leave our infrastructure, so the off-site provider holds only encrypted data, and the passphrase is kept separately from the server.
Restores are tested, not assumed. Our procedure restores the most recent dump into a throwaway database and verifies row counts against the original. This has been running in production since July 2026.
Because backups run nightly, the worst case for data loss in a total-failure scenario is up to 24 hours. We do not currently offer a contractual recovery-time commitment, and we would rather say that than quote a number we haven’t measured.
7. Privacy
Our Privacy statement is the full account, structured around the 13 Information Privacy Principles in the Privacy Act 2020. In short:
- We collect what we need to run your account — name, email, organisation, and what you looked up, for quotas, billing and support.
- We use no tracking or advertising cookies, and this marketing site carries no analytics at all. It makes no third-party network requests: even the fonts are served from our own domain. Browser session storage is used only for functional things, like resuming an interrupted sign-in.
- Billing and account-audit records are kept for 7 years, in line with the Tax Administration Act 1994. Working content — watchlists, notes, search history, generated reports — is deleted when your account closes.
- Register data about individuals is shown for lawful business research. We do not use it for marketing lists, and our terms prohibit our users from using it for profiling, harassment or stalking. Residential addresses are stored but never shown prominently — they sit behind a collapsed section and an explicit action.
- We have a named privacy officer, and we will notify affected individuals and the Office of the Privacy Commissioner of any privacy breach likely to cause serious harm, as the Act requires.
8. Certifications — what we hold, and what we don’t
We would rather tell you this directly than have you discover it halfway through a procurement process.
What we hold
- Licensed access agreements with MBIE and the Companies Office covering every register we draw on, as set out in section 2. This is the substantive assurance in our category: our data provenance is contractual and auditable.
What we don’t hold, and why
- SOC 2 and ISO 27001. We are not certified against either. Both are meaningful, and both cost more in their first year than a business serving customers at $39 a month can honestly justify. We maintain the practices underneath them — least-privilege access, encrypted and restore-tested backups, audit logging, a documented recovery procedure — and we will pursue certification when a customer’s requirements justify it rather than as marketing. If your organisation has a security questionnaire, send it to us and we will complete it.
- AML/CFT vendor accreditation. No such scheme exists in New Zealand. The statutory review of the AML/CFT Act recommended exploring one; it was never established, so no vendor holds one. Treat any claim to the contrary with suspicion.
- A New Zealand cloud-provider code of practice. There isn’t a live one to join — the industry CloudCode scheme has been inactive for years and its register is now offline. We publish our own disclosure of the same material instead, on this page.
- Digital Identity Services Trust Framework accreditation. Not applicable to us, and worth being clear about: Legible verifies no natural person, collects no identity documents, and interacts with no end customer. It is a research and intelligence tool, not an identity-verification or customer-onboarding service.
9. Reporting a vulnerability
If you believe you have found a security vulnerability in Legible, please email privacy@legible.nz with enough detail for us to reproduce it.
We will acknowledge your report within two working days, keep you informed while we fix it, and we will not pursue action against anyone who reports a genuine issue in good faith and does not access, alter or retain other customers’ data in the process.
For anything else about security, privacy or data handling — including a questionnaire you need filled in — the same address reaches us, or use the contact form.