Trust
Security & Trust
What we do today to protect your data, stated plainly. Where we do not yet have something, such as a third-party certification, we say so. For live verification dates, see our Trust Center.
1. Where your data lives
Searchestra runs on DigitalOcean in the Frankfurt, Germany region (EU). The application, its services, its database and its object storage run in that region. Some processing by the AI providers listed under sub-processors takes place outside the EU and Türkiye.
2. Encryption in transit
Every public Searchestra domain is served only over HTTPS with TLS 1.2 or 1.3. HTTP Strict Transport Security is enabled, so browsers do not fall back to unencrypted connections.
3. Accounts and credentials
Passwords are stored only as bcrypt hashes; we cannot read them.
Password reset links are single-use, expire after one hour and stop working once the password has been changed.
API keys are stored only as hashes. The full key is shown once, when you create it.
4. Access control
Access is organized by organization and brand. Members see and act only on the brands they have been given access to, with roles set per brand.
5. What we send to AI providers
For measurement, we send brand-neutral category questions to the AI platforms in our catalog and to search-data providers. These questions do not contain your business data.
For analysis, we send the answers we collect, your public website content and the brand information you enter (such as your brand profile, competitors and knowledge-base sources) to AI analysis models. They classify answers, detect brands and sentiment, and help build your setup and content.
We send only what a feature needs. Results are stored in your organization’s workspace, scoped to the brand and market they measure.
6. Sub-processors
The current list of providers we use to run Searchestra, with the countries where they process data and the transfer mechanism for each, is on our Sub-processors page. It is published from our processor registry, and we announce a new provider 30 days before it takes effect.
For the data each provider receives, see our Privacy Notice.
7. Retention and deletion
We keep account and measurement data while your account is active. To delete a brand’s data or your whole account, email us; on account deletion we remove personal data within 30 days, except where the law requires us to keep it.
8. Certifications
We do not currently hold SOC 2 or ISO 27001 certification. For procurement reviews, we answer security questionnaires and review data processing terms with your team.
9. Reporting a security issue
If you believe you have found a vulnerability in Searchestra, tell us privately. Email security@searchestra.com or use the form below. Our contact details are also published in security.txt.
What to include. The affected URL or feature, the steps to reproduce, what an attacker could do with it, and any proof of concept. Tell us how to reach you if you want updates.
What we do. We acknowledge reports within 3 business days, share our assessment within 10 business days and keep you updated until the issue is fixed. We fix confirmed critical issues within 7 days and high-severity issues within 30 days.
Safe harbor. We will not take legal action against research done in good faith under this policy. Please test only with accounts you own, do not access, change or delete other customers’ data, do not degrade the service (no denial-of-service or load testing), do not use social engineering or physical attacks, and give us reasonable time to fix the issue before you disclose it publicly.
We do not run a paid bug bounty program. With your permission, we are happy to credit you once the issue is fixed.
Thank you
We received your report and will reply from security@searchestra.com within 3 business days. Please keep the details private while we look into it.