Security & trust

Your data,
defended in depth.

Smart SEO Audit was built with security as a first-class concern from day one — not bolted on after the first audit. Here's exactly how we protect your account, your audits and your client data.

Swiss-hosted AES-256 encrypted GDPR & FADP Disclosure program
Our security model

Four pillars.
One mandate: protect your data.

Every architectural decision starts here. If something can't be done safely, we don't ship it.

Infrastructure

Hardened, Swiss-hosted infrastructure with redundant backups and 24/7 monitoring. No single point of failure, no surprise data-residency.

  • Tier-3 Swiss data centers, ISO-27001 certified facility
  • Automated, encrypted off-site backups (35-day retention)
  • DDoS protection and WAF in front of all public endpoints
  • Documented disaster-recovery plan, tested quarterly

Data protection

Your audit data is encrypted, isolated and never sold. Defense in depth means breaking one layer doesn't compromise the rest.

  • AES-256 encryption at rest for all customer data and backups
  • TLS 1.3 in transit with HSTS enforced site-wide
  • Passwords stored using Argon2id with per-user salts
  • Tenant isolation at the database row level

Access control

Strict, audited access — for both customers managing their accounts and our internal team supporting them.

  • Two-factor authentication available on every account
  • SSO available on Agency and Enterprise plans
  • Principle of least privilege for all internal access
  • All admin actions logged and reviewable on request

Incident response

When something goes wrong, you'll know — fast and honestly. We rehearse this stuff so it works when it matters.

  • Documented incident response runbook
  • Breach notification within 72 hours, as required by GDPR
  • Public status page for service incidents
  • Post-mortems published for major incidents
The technical details

No marketing fluff.
Just the specs.

If you're a security engineer doing a vendor review, this is the one-pager you're looking for.

Encryption · in transit
TLS 1.3

HSTS enforced site-wide. TLS 1.0/1.1 disabled. A+ rating on SSL Labs.

Encryption · at rest
AES-256

Customer data and backups encrypted with envelope encryption and per-tenant keys.

Password storage
Argon2id

Modern memory-hard hashing with per-user salts. Plaintext passwords are never stored or logged.

Hosting region
Switzerland 🇨🇭

Tier-3 Swiss data centers. Outside EU and US jurisdictions for primary data storage.

Backup retention
35 days

Encrypted, off-site, tested with quarterly restore drills.

Uptime target
99.9%

Measured monthly, excluding scheduled maintenance. Public status page available.

Authentication
Email + 2FA

TOTP-based two-factor on every plan. SAML SSO on Agency and Enterprise.

Vulnerability scanning
Continuous

Automated SCA on every dependency change, plus periodic external pen tests.

Incident response
<72h notification

GDPR-compliant breach notification process with on-call escalation.

Compliance & certifications

Built to clear
vendor reviews.

Procurement teams ask for these. Here's where we stand — including what's live today and what's on the roadmap.

● Live
GDPR

Full EU General Data Protection Regulation compliance. DPA available on request. Sub-processor list maintained and updated.

● Live
Swiss FADP

Compliant with the revised Swiss Federal Act on Data Protection (in force since September 2023). Switzerland is a recognized adequate jurisdiction.

● Live
DPA on request

Pre-signed Data Processing Agreement with EU Standard Contractual Clauses available — email [email protected].

⏳ Roadmap
SOC 2 Type II

Audit underway. Type I report targeted for late 2026, Type II to follow. We'll share progress publicly as we hit milestones.

Responsible disclosure

Found a bug?
We owe you a thank-you.

If you've discovered a security vulnerability in Smart SEO Audit, please report it directly to our security team. We acknowledge every legitimate report, work with you to validate and fix the issue, and credit researchers (with consent) on a public hall of fame.

Acknowledgment within 48 hours
No legal action against good-faith research
Public credit on our hall of fame (with consent)
Bounties for high-severity findings, case-by-case
Report a vulnerability
[email protected]

PGP key available at /.well-known/security.txt. Please include reproduction steps and your assessed severity.

SCOPE & RULES

What's in scope, what isn't.

A short, honest list — to save your time and ours.

  • In scope: smartseoaudit.com, app.smartseoaudit.com, public APIs, the audit engine itself.
  • Out of scope: third-party services we don't control, social engineering, physical attacks, DoS/DDoS testing.
  • Please don't: access other users' data, run automated scanners against production, publicly disclose before we patch.
  • Please do: use a test account, throttle your testing, and give us a reasonable window to fix before going public.
Data handling

Where your data goes.
And where it doesn't.

Three short policies that explain how we treat your information end-to-end.

Stays in Switzerland

Primary storage and processing happens in Swiss data centers. Limited sub-processor data (payments, transactional email, AI insights) may transit other regions under SCC-equivalent safeguards. Full sub-processor list available on request.

Never sold, never trained

Your audit data is never sold, rented, or used to train AI models for anyone else. We use it only to provide the Service to you. Written into our Terms and Privacy Policy.

Deleted on request

Cancel your account and your audit history is permanently removed within 30 days. Backups roll off within 35 days after that. GDPR data-export and deletion requests answered within 30 days.

Frequently asked questions

Quick answers for
vendor reviews.

The four questions every procurement team and security engineer asks first.

Where is Smart SEO Audit data hosted?
All customer data is hosted in Tier-3 data centers in Switzerland, outside the EU and US, under one of the strictest data-protection regimes worldwide.
How is data encrypted?
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Backups are equally encrypted.
Is Smart SEO Audit GDPR-compliant?
Yes. Smart SEO Audit complies with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP). A Data Processing Agreement (DPA) is available on request.
How can I report a security vulnerability?
Email [email protected] with details. We acknowledge reports within 48 hours and follow a structured responsible-disclosure process.
SECURE BY DESIGN

Audit with
confidence.

Swiss-hosted · GDPR-compliant · AES-256 encrypted