Trust
Trust Center
The security controls we run today. Every item below is backed by automated tests that run on each change. Where a control depends on something that has to happen regularly, such as a restore test, we show when it was last verified. If that evidence is missing or out of date, we say so.
In place implemented and covered by tests. Verified recent evidence, with its date. Awaiting verification the evidence is missing or older than our standard.
Data protection
- Encryption in transitIn place
Every public Searchestra domain is served only over HTTPS with TLS 1.2 or 1.3, and HTTP Strict Transport Security is enabled.
- Encrypted integration credentialsIn place
Credentials you give us for integrations are encrypted before they are stored, with keys kept apart from the data.
- Customer-managed keysIn place
Enterprise organizations can encrypt integration credentials and generated files with their own AWS KMS key. If the key is disabled, that data can no longer be decrypted.
- EU hostingIn place
The application, database and file storage run in the EU (Frankfurt, Germany). An organization’s region is set when it is created and does not change. Some AI processing happens outside the EU; see Sub-processors.
Identity and access
- Password storageIn place
Passwords are stored only as bcrypt hashes. Reset links are single-use and expire after one hour.
- Multi-factor authenticationIn place
Authenticator-app codes with single-use recovery codes. Owners can require it for admins or for every member.
- Single sign-onIn place
SAML 2.0 and OpenID Connect for verified domains. Owners can require SSO, with an owner-only emergency path.
- SCIM provisioningIn place
Create, update and remove members and group roles automatically from your identity provider with SCIM 2.0.
- Tenant isolationIn place
Every request is scoped to your organization and brands. Access to another organization’s data is tested for each resource type.
- IP allowlistIn place
Organizations can limit the panel, the API and SCIM to their own network ranges.
- Audit logIn place
Security-relevant actions are recorded in a tamper-evident audit log that organization admins can review.
Operations
- BackupsIn place
Continuous encrypted database backups in the EU with point-in-time recovery. Files are copied to a second EU region.
- Restore testingChecking
Every week we restore a backup into an isolated environment and check it automatically. The status shows the last successful test; it counts as current for 14 days.
- Incident responseIn place
Security incidents are handled through a documented process. If an incident affects your data, we notify your organization’s owners and security contacts without undue delay.
Security program
- Vulnerability managementIn place
Every reported or found vulnerability is tracked with a fix deadline by severity: 7 days for critical, 30 for high, 90 for medium and 180 for low. Report an issue.
- Penetration testingChecking
Our standard is an independent test every 12 months covering sign-in, SSO, SCIM, tenant isolation, shared reports, API keys and integrations, with no open critical or high findings. The status shows whether the last 12 months meet it.
- Software supply chainIn place
Dependencies and container images are scanned on every change, and releases with fixable high or critical vulnerabilities are blocked. Release images are signed, and the signature is checked on the server before they run.
Privacy
- Sub-processorsChecking
A public, versioned list of the providers we use, with 30 days’ notice before a new one takes effect. See the list.
- Privacy requestsIn place
Download or delete your data from Settings, or send a request through our privacy request form. We respond within 30 days.
- Retention and deletionIn place
Every kind of data we store has a documented retention period, and time-based deletion runs automatically. Deleted data may remain in encrypted backups for up to 45 days.
Certifications
Having a control in place is not the same as being certified. We list a certification only after an independent auditor has issued it.
- SOC 2 Type IINot certified
We do not hold this certification today.
- ISO/IEC 27001Not certified
We do not hold this certification today.
Documents and questionnaires
For security and procurement reviews we share documents such as our completed security questionnaire, penetration test summary and data processing agreement. Request them below with your work email. We review each request and email you a personal link that works for 7 days; you accept confidentiality terms before downloading.
Request received
We review requests within 3 business days. If we approve yours, you’ll get an email with a personal link to the documents.
Something else? Email security@searchestra.com.
More detail: Security, Privacy Notice, Cookie Notice, Sub-processors, Data portability, security.txt.