for your information
A plain-language summary of where the data lives, who can touch it, and what happens when things break. Aimed at procurement, but useful for anyone curious.
All datasets in eolas come from public NZ government and intergovernmental sources. We don't generate or transform the underlying values — we package the data into one consistent API.
Every /v1/datasets/{name}/data, /v1/bulk/…, and changelog feed response carries X-Eolas-Attribution and X-Eolas-Licence headers (same wording as bulk NOTICE.txt). Snowflake share consumers query eolas.EOLAS_META.ATTRIBUTIONS.
Every dataset detail page links to the canonical source so you can verify lineage yourself. We have no exclusive rights to any of this data — you could always fetch it directly. eolas just saves you the scraping.
ap-southeast-2) — the closest commercial region to New Zealand.eolas-web, vs-api) on AWS ECS Fargate behind an Application Load Balancer, fronted by Cloudflare (proxied — WAF + DDoS protection). Origin access is restricted to Cloudflare: Authenticated Origin Pulls (mutual TLS) and a security group locked to Cloudflare's IP ranges./health/full every 3 minutes from outside AWS; email alerts on failure.frame-ancestors), X-Frame-Options, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy, HSTS — enforced on the public edge and version-controlled in the platform config.X-API-Key verified by SHA-256 hash; the displayable copy is encrypted at rest (Fernet). Rotate any key from your dashboard.sk_live_.git archive / image builds from committed sources), never a working tree.If something breaks badly enough to affect customers — outage, data quality regression, security event — here's what happens:
Report a vulnerability privately at [email protected]. We commit to acknowledging within one working day. A public /.well-known/security.txt also points here.
In June 2026 the public web surface was assessed with a non-destructive OWASP Top 10 (2021)-aligned automated scan (BountyShield / owasp-url-scanner). Findings related to security headers and clickjacking defences were remediated; the live site now ships HSTS, CSP (including frame-ancestors), and related headers.
This was an automated assessment, not a full human penetration test or a SOC 2 / ISO 27001 audit. The report is available under NDA on request. A human penetration test of the web and API surface can be commissioned as part of enterprise onboarding.
Third parties that process data on eolas's behalf. The datasets themselves are public; the only customer data involved is account/billing metadata.
ap-southeast-2).We'll give notice of material subprocessor changes to Enterprise customers under contract. A Data Processing Addendum is available on request.
If you're doing procurement diligence, we can fill out a vendor security questionnaire on request.
Get in touch