Skip to main content
Security overview

Controls for accounts, organizations, data, and integrations

This page describes controls implemented in SERP Checker. It does not claim a certification or replace your own vendor-risk assessment.

Account protection

Passwords are hashed, sessions use secure cookie controls, login attempts are rate-limited, email verification is supported, and accounts can enable time-based two-factor authentication with backup codes.

Organization isolation

Customer data is scoped to an organization and checked at route and API boundaries. Roles separate members, organization administrators, and platform superadministrators. Sensitive administrative actions are recorded in the audit log.

Data and integrations

API keys are named and revocable. Provider secrets are kept in server configuration and are not rendered back to browsers. Public reports use unguessable share tokens and can be protected with a password. Backups and restore evidence are monitored by platform operators.

Reporting a security issue

Do not include live credentials or customer data in an initial report. Use the Sales and Security contact form and select Security review so the issue can be routed privately.

Need a security review?

Send your questionnaire or describe the control you need to verify. Do not include credentials in the form.

Request security information