Security with clear boundaries.
AWS hosted infrastructure, documented privacy measures, and a transparent view of our SOC 2 and GDPR readiness work. We publish what we can support with evidence and label everything else as work in progress.
Honesty matters more than badges.
Every status below separates published measures from readiness work and independent assurance. The wording comes straight from our evidence registry, so this page cannot drift ahead of what we can show.
We maintain a Privacy Policy, Data Processing Addendum, sub-processor list, data-subject request channel, encryption controls, and retention controls. Our GDPR control review is ongoing and is not a legal determination of compliance.
Our UAE PDPL control review is ongoing. The published privacy documents describe the measures and request channels currently documented for SearchChamp.
No independent SOC 2 examination has been completed for SearchChamp. SOC 2 readiness work and operating-evidence collection are ongoing.
Privacy documents, a data-subject request channel, and category-specific retention controls are documented. End-to-end operating evidence for data-subject requests remains part of the readiness programme.
Four layers, described precisely.
SearchChamp agents read keyword data, search console metrics, and website content to deliver SEO and AI search insights. These are the controls around that access, stated the same way we state them in the legal overview.
AWS, eu-west-1 (Ireland)
- The platform runs on AWS in the eu-west-1 (Ireland) region, keeping EEA customer data hosted inside the European Economic Area.
- The production database sits in private subnets, and selected worker tiers use private VPC networking.
- Public traffic enters through AWS managed web and API endpoints, with CloudFront and AWS Shield Standard in front of static assets.
Encrypted in transit and at rest
- AWS-managed storage services used for customer data are configured for encryption at rest, and public web and API traffic uses HTTPS. Coverage is assessed per system rather than claimed universally.
- The production RDS PostgreSQL database and its automated daily backups are encrypted with AWS KMS managed keys, with backups retained for 7 days.
- TLS policy is configured at the AWS managed edge and API services for reviewed endpoints.
Least privilege by default
- Customer authentication is managed by AWS Cognito. Passwords are stored with Cognito's secure hashing and never in plain text.
- Optional TOTP based MFA is available to all users. Access tokens expire after 1 hour and refresh tokens after 30 days.
- SearchChamp uses authenticated application authorization and workspace-scoped access checks. Control scope and operating evidence are reviewed per system.
Reviewed at the boundaries
- Our development process includes review against the OWASP Top 10, covering injection, XSS, CSRF, and broken authentication.
- API boundaries use TypeScript validation, Zod schemas, parameter binding, and targeted security guards according to the service and request path.
- SearchChamp maintains secret-management controls that are reviewed per deployed service. Readiness evidence is still being assembled.
The raw IP address stays out of the database.
SearchChamp's crawler analytics confirm that an AI crawler is who it claims to be. A user agent string alone proves nothing, so we verify the source IP against the vendor's published ranges. How we handle that IP is unusual enough to draw.
Crawler visit
A request matching a known bot user agent fires the beacon. Human visitors never trigger it.
Verified in memory
The source IP is checked against the vendor's published IP ranges at ingest time, before anything is written.
One way hash
Only then is the IP hashed. In this pipeline the raw address is not written to the database or to logs.
Hash and verdict stored
What persists is the hash plus an honest verdict: verified, pending, or unverifiable. Never falsely verified.
This guarantee is specific to the verified bot pipeline above. When a visitor requests a report from one of our free SEO tools, that submission's IP address is stored in raw form for abuse prevention, with a rolling 6-month deletion control. Section 7 of the Privacy Policy sets out the details.
When an agent calls a third party model, it sends task inputs such as page text, keywords, and search console metrics under the provider's commercial API terms. We use reduced retention options where available and review minimisation by feature and provider.
Production CloudWatch log groups use a 90-day minimum-retention control, verified bot visit records use a rolling 90-day window, and free tool submission IPs use a rolling 6-month deletion control. The Privacy Policy holds the published schedule.
Documents that back this page.
Nothing here asks you to take our word for it. Each claim above traces to a published document you can read in full.
Customers on Pro and Agency plans may request a copy of our security questionnaire responses under NDA at security@searchchamp.com.
Found something? Tell us first.
If you discover a vulnerability in the SearchChamp platform, email security@searchchamp.com with a description of the issue and steps to reproduce it. We review incoming reports and coordinate next steps based on severity and available evidence.
- Give us at least 90 days to investigate and remediate before public disclosure.
- Avoid accessing or modifying customer data beyond what is needed to demonstrate the issue.
- Do not run denial of service tests or disrupt the service for other users.
We do not offer a paid bug bounty programme at this time. With your permission, we will credit you publicly once the issue is resolved.
security@searchchamp.comSecurity questions?
Ask for the current security overview, request questionnaire responses under NDA, or report an issue.