Security
Last updated: 2026-09-02
Security controls described with clear boundaries.
1. Overview
Atlio Limited (“Atlio Limited”), a company registered in New Zealand with a UAE branch (Atlio Information Technology LLC), takes the security of customer data seriously. Our AI agents read keyword data, search-console metrics, and website content to deliver SEO and AI-search insights. This page describes the controls we can support with current evidence and identifies important readiness work that remains open.
This overview is intended for customers, prospects, agencies, and security researchers evaluating SearchChamp. It is not a certification, audit opinion, or legal conclusion. SearchChamp is a product of Atlio Limited.
2. Compliance and certifications
Honesty matters more than badges. The statuses below distinguish published measures from readiness work and independent assurance.
We maintain a Privacy Policy, Data Processing Addendum, sub-processor list, data-subject request channel, encryption controls, and retention controls. Our GDPR control review is ongoing and is not a legal determination of compliance.
No independent SOC 2 examination has been completed for SearchChamp. SOC 2 readiness work and operating-evidence collection are ongoing.
| Standard / Framework | Status | Evidence boundary |
|---|---|---|
| GDPR | Control review ongoing | Published privacy documents and repository-visible controls; no legal conclusion |
| UAE PDPL | Control review ongoing | Published privacy documents and repository-visible controls; external legal review required |
| SOC 2 | No independent examination completed | Readiness mapping only; no SearchChamp report or certification |
| ISO 27001 | No SearchChamp certification claimed | Not independently assessed in this review |
Customers on Pro and Agency plans may request a copy of our security questionnaire responses under NDA by contacting security@searchchamp.com.
3. Security pillars at a glance
Four layers, each with a concrete control rather than a marketing claim:
Infrastructure
AWS, eu-west-1
Primary AWS infrastructure in eu-west-1, with database and worker tiers placed in private subnets.
Encryption
TLS 1.3 + AES-256
AWS-managed storage encryption and HTTPS controls are reviewed per system.
Access
Cognito and application authorization
Customer TOTP MFA is optional. Access-control scope and evidence are reviewed per system.
App security
OWASP, Zod, dependency alerts
Security review covers common web risks; schema validation, parameter binding, and dependency checks are applied at reviewed boundaries.
4. Infrastructure
The SearchChamp platform is hosted on Amazon Web Services (AWS) in the eu-west-1 (Ireland) region. We chose Ireland as our primary region to keep EEA customer data within the European Economic Area.
- Network isolation: the database is deployed in private subnets, and selected worker tiers use private VPC networking. Public application traffic enters through AWS-managed web and API endpoints.
- Compute: application logic primarily runs on AWS Lambda with service-specific network and permission boundaries.
- Database: RDS PostgreSQL 16 (production) with automated daily backups retained for 7 days, encrypted with AWS KMS.
- CDN and DDoS protection: static assets and marketing pages are served through AWS CloudFront with AWS Shield Standard enabled.
- Availability: service monitoring and backup controls are assessed per system as readiness evidence is assembled.
5. Encryption
5.1 Encryption in transit
Public SearchChamp web and API endpoints use HTTPS. TLS policy is configured at the AWS-managed edge and API services for reviewed endpoints.
Service-to-service transport protections depend on the AWS service and connection path and are reviewed per system.
5.2 Encryption at rest
AWS-managed storage services used for customer data are configured for encryption at rest:
- RDS PostgreSQL database: encrypted with AWS KMS-managed keys (aws/rds).
- Database backups: encrypted with AWS KMS.
- Secret-management controls: reviewed per deployed service as part of the readiness programme.
- S3 buckets (logs, exports): server-side encryption with S3-managed keys (SSE-S3).
5.3 Secrets management
SearchChamp maintains secret-management controls that are reviewed per deployed service. Readiness evidence is still being assembled.
6. Access controls and tenant isolation
6.1 Internal access
Access to production infrastructure is governed by the principle of least privilege:
- Production database network access is restricted through private networking and administrative paths.
- AWS IAM roles are assigned by deployed service and reviewed within each service boundary.
- Administrative and repository access controls are reviewed per system and role.
- AWS control-plane activity is recorded by CloudTrail and assessed according to event type.
6.2 Customer access controls
- Authentication: managed by AWS Cognito. Passwords are stored using AWS Cognito's secure hashing and never stored in plain text.
- MFA: optional TOTP-based MFA is available to all users.
- Session management: access tokens expire after 1 hour. Refresh tokens expire after 30 days.
6.3 Your data, your tenants
SearchChamp uses authenticated application authorization and workspace-scoped access checks. Control scope and operating evidence are reviewed per system.
7. Application security
- OWASP Top 10: our development process includes review against the OWASP Top 10 for common web application vulnerabilities including injection, XSS, CSRF, and broken authentication.
- Input validation: API boundaries use TypeScript validation, Zod schemas, parameter binding, and targeted security guards according to the service and request path.
- Dependency scanning: repository dependency alerts inform risk-based triage and remediation.
- Abuse controls: rate limits and quotas are applied according to endpoint risk and service design.
- Audit logging: authentication, workspace, administrative, and service events are recorded across category-specific stores. Event scope and retention are reviewed per system.
8. Data handling and privacy by design
We collect what the product needs to work, and no more. Two practices are worth calling out because they are unusual and verifiably true.
8.1 Verified-bot analytics: raw IPs are never persisted
SearchChamp’s GEO module tells you which AI crawlers are actually reading your site. To do that honestly, it has to confirm a crawler is who it claims to be; a user-agent string alone proves nothing and is trivially spoofed.
So when a crawler visit is captured, we verify the source IP against the vendor’s published IP ranges in memory, at ingest time, and only then hash the IP. The raw IP address is never written to the database, never logged, and never leaves the request. What persists is a one-way hash plus a verification verdict: we label a visit “Verified” only when the IP or ASN actually confirms the vendor; an unconfirmed visit is recorded as pending or unverifiable, never falsely as verified. The beacon that powers this only fires on a matched bot user-agent, so no human visitor’s IP is involved at any point.
This is privacy by design: you get trustworthy crawler attribution without us hoarding raw network identifiers.
This guarantee is specific to the verified-bot crawler pipeline described above; it is not a site-wide statement about every IP address we handle. In particular, when a visitor requests a report from one of our free SEO tools, the IP address that submission came from is stored in raw form on the submission record, for abuse prevention. What we collect there and how long we keep it is set out in section 7 of our Privacy Policy.
8.2 Data minimisation to AI providers
When an agent calls a third-party model, it sends task inputs such as page text, keywords, and search-console metrics under the provider’s commercial API terms. We use reduced-retention options where available and continue to review minimisation by feature and provider.
8.3 Retention and deletion
Retention is category-specific. Production CloudWatch log groups use a 90-day minimum-retention control, while audit records may be retained longer. Verified-bot visit records use a rolling 90-day window, and free-tool submission IP addresses use a rolling 6-month deletion control. See our Privacy Policy for the published schedule and request channels.
9. Sub-processors and vendor security
We use sub-processors for infrastructure, AI, SEO data, payments, and connected services. Current providers, purposes, data categories, and processing locations are listed on our sub-processors page:
- Anthropic (Claude): powers AI-agent features under Anthropic’s commercial API terms.
- OpenAI: provides additional AI-agent and AI-visibility coverage under OpenAI’s API terms.
- DataForSEO: keyword, SERP, and backlink data. Queries are limited to keywords, URLs, and domain names and are not intended to contain personal data.
- Stripe: billing and payments. PCI-DSS Level 1 certified; raw card data never passes through SearchChamp servers.
- Google: Search Console and Analytics integrations and AI Overview tracking, connected with your explicit OAuth consent and revocable at any time.
- AWS: hosting, Cognito authentication, storage, and related cloud services.
The published list of sub-processors, purposes, data categories, and processing locations is maintained at /legal/sub-processors and reviewed through the privacy programme. Notice commitments are described in our Data Processing Addendum.
10. Incident response
Atlio Limited maintains a documented personal-data-breach runbook. Incident-response and recovery evidence is assembled and reviewed as part of the readiness programme.
- Detection: CloudWatch alarms cover availability, error, queue, and security signals according to service-specific monitoring scope.
- Notification: processor notification commitments are described in the Data Processing Addendum and apply without undue delay after awareness of a relevant personal data breach.
- Response review: response ownership, escalation, and recovery evidence is assessed through the readiness programme.
- Learning: the engineering process records post-incident analysis where applicable; customer communications depend on incident scope and contractual obligations.
11. Vulnerability disclosure
We operate a responsible disclosure programme. If you discover a security vulnerability in the SearchChamp platform, please email security@searchchamp.com with a description of the issue and steps to reproduce it. We ask that you:
- Give us at least 90 days to investigate and remediate before public disclosure;
- Avoid accessing or modifying customer data beyond what is required to demonstrate the vulnerability;
- Not perform denial-of-service attacks or disrupt services for other users.
We aim to respond to reports within 2 business days and, with your permission, will credit you publicly once the issue is resolved. We do not offer a paid bug bounty programme at this time.
12. Contact
Security enquiries, responsible disclosure reports, and security questionnaire requests:
Atlio Limited (New Zealand)UAE branch: Atlio Information Technology LLC, Dubai, United Arab Emirates
Email: security@searchchamp.com