Skip to content
Security

Security with clear boundaries.

AWS hosted infrastructure, documented privacy measures, and a transparent view of our SOC 2 and GDPR readiness work. We publish what we can support with evidence and label everything else as work in progress.

Compliance and certifications

Honesty matters more than badges.

Every status below separates published measures from readiness work and independent assurance. The wording comes straight from our evidence registry, so this page cannot drift ahead of what we can show.

GDPR

We maintain a Privacy Policy, Data Processing Addendum, sub-processor list, data-subject request channel, encryption controls, and retention controls. Our GDPR control review is ongoing and is not a legal determination of compliance.

UAE PDPL

Our UAE PDPL control review is ongoing. The published privacy documents describe the measures and request channels currently documented for SearchChamp.

SOC 2

No independent SOC 2 examination has been completed for SearchChamp. SOC 2 readiness work and operating-evidence collection are ongoing.

Privacy operations

Privacy documents, a data-subject request channel, and category-specific retention controls are documented. End-to-end operating evidence for data-subject requests remains part of the readiness programme.

Evidence statusreviewed 26 Aug 2026
Privacy Policypublished
Data Processing Addendumpublished
Sub-processor listpublished
Encryption configurationconfigured
GDPR control reviewongoing
UAE PDPL control reviewongoing
SOC 2 examinationnot completed
No certification badge claimed
The controls

Four layers, described precisely.

SearchChamp agents read keyword data, search console metrics, and website content to deliver SEO and AI search insights. These are the controls around that access, stated the same way we state them in the legal overview.

Infrastructure

AWS, eu-west-1 (Ireland)

  • The platform runs on AWS in the eu-west-1 (Ireland) region, keeping EEA customer data hosted inside the European Economic Area.
  • The production database sits in private subnets, and selected worker tiers use private VPC networking.
  • Public traffic enters through AWS managed web and API endpoints, with CloudFront and AWS Shield Standard in front of static assets.
Encryption

Encrypted in transit and at rest

  • AWS-managed storage services used for customer data are configured for encryption at rest, and public web and API traffic uses HTTPS. Coverage is assessed per system rather than claimed universally.
  • The production RDS PostgreSQL database and its automated daily backups are encrypted with AWS KMS managed keys, with backups retained for 7 days.
  • TLS policy is configured at the AWS managed edge and API services for reviewed endpoints.
Access

Least privilege by default

  • Customer authentication is managed by AWS Cognito. Passwords are stored with Cognito's secure hashing and never in plain text.
  • Optional TOTP based MFA is available to all users. Access tokens expire after 1 hour and refresh tokens after 30 days.
  • SearchChamp uses authenticated application authorization and workspace-scoped access checks. Control scope and operating evidence are reviewed per system.
Application security

Reviewed at the boundaries

  • Our development process includes review against the OWASP Top 10, covering injection, XSS, CSRF, and broken authentication.
  • API boundaries use TypeScript validation, Zod schemas, parameter binding, and targeted security guards according to the service and request path.
  • SearchChamp maintains secret-management controls that are reviewed per deployed service. Readiness evidence is still being assembled.
Privacy by design

The raw IP address stays out of the database.

SearchChamp's crawler analytics confirm that an AI crawler is who it claims to be. A user agent string alone proves nothing, so we verify the source IP against the vendor's published ranges. How we handle that IP is unusual enough to draw.

01

Crawler visit

A request matching a known bot user agent fires the beacon. Human visitors never trigger it.

02

Verified in memory

The source IP is checked against the vendor's published IP ranges at ingest time, before anything is written.

03

One way hash

Only then is the IP hashed. In this pipeline the raw address is not written to the database or to logs.

04

Hash and verdict stored

What persists is the hash plus an honest verdict: verified, pending, or unverifiable. Never falsely verified.

This guarantee is specific to the verified bot pipeline above. When a visitor requests a report from one of our free SEO tools, that submission's IP address is stored in raw form for abuse prevention, with a rolling 6-month deletion control. Section 7 of the Privacy Policy sets out the details.

Data minimisation to AI providers

When an agent calls a third party model, it sends task inputs such as page text, keywords, and search console metrics under the provider's commercial API terms. We use reduced retention options where available and review minimisation by feature and provider.

Category specific retention

Production CloudWatch log groups use a 90-day minimum-retention control, verified bot visit records use a rolling 90-day window, and free tool submission IPs use a rolling 6-month deletion control. The Privacy Policy holds the published schedule.

Responsible disclosure

Found something? Tell us first.

If you discover a vulnerability in the SearchChamp platform, email security@searchchamp.com with a description of the issue and steps to reproduce it. We review incoming reports and coordinate next steps based on severity and available evidence.

  • Give us at least 90 days to investigate and remediate before public disclosure.
  • Avoid accessing or modifying customer data beyond what is needed to demonstrate the issue.
  • Do not run denial of service tests or disrupt the service for other users.

We do not offer a paid bug bounty programme at this time. With your permission, we will credit you publicly once the issue is resolved.

security@searchchamp.com

Security questions?

Ask for the current security overview, request questionnaire responses under NDA, or report an issue.