Account protection
Passwords are hashed, sessions use secure cookie controls, login attempts are rate-limited, email verification is supported, and accounts can enable time-based two-factor authentication with backup codes.
This page describes controls implemented in SERP Checker. It does not claim a certification or replace your own vendor-risk assessment.
Passwords are hashed, sessions use secure cookie controls, login attempts are rate-limited, email verification is supported, and accounts can enable time-based two-factor authentication with backup codes.
Customer data is scoped to an organization and checked at route and API boundaries. Roles separate members, organization administrators, and platform superadministrators. Sensitive administrative actions are recorded in the audit log.
API keys are named and revocable. Provider secrets are kept in server configuration and are not rendered back to browsers. Public reports use unguessable share tokens and can be protected with a password. Backups and restore evidence are monitored by platform operators.
Do not include live credentials or customer data in an initial report. Use the Sales and Security contact form and select Security review so the issue can be routed privately.
Send your questionnaire or describe the control you need to verify. Do not include credentials in the form.
Request security information