Security

Your data, handled carefully.

What we connect to, what we store, what we will never do with your data, and where our compliance posture honestly stands today.

01 · What we hold

What we hold, and what we never do with it.

Five commitments, written as constraints we operate under rather than badges we award ourselves.

A ruled custody ledger held shut by thread wound between two seal buttons, a lock stamp, and a chain of tagged seals running off the bottom edge.The custody record

Held under your terms

Your accounts stay the source of truth.

Every holding below is revocable from your own Google, CMS, or CRM account without asking us. Published pages live on your infrastructure, not ours.

01

We never train AI models on your data

Not on your published content, not on your Search Console or Analytics data, not on anything in your CRM. Our model providers operate under commercial terms that prohibit training on customer content, and Google's API policy separately prohibits using Search Console or Analytics data to train generalized models.

02

Least-privilege access you can revoke

Each connection asks for the narrowest scope that lets it do its job: read-only wherever reading is enough, content-write only where publishing requires it. We never request access to customer records, orders, or billing on your platforms. Every connection is revocable from your own Google, CMS, or CRM account without asking us.

03

Encrypted in transit and at rest

Traffic runs over TLS, and stored data is encrypted at rest by our hosting provider. We deliberately avoid phrases like bank-level or military-grade encryption: they are marketing terms with no technical definition behind them.

04

We never sell or share your data

Your content, search data, and performance figures are used to run your account and nothing else. We do not sell data, we do not build an aggregate data product from it, and we do not share it with advertisers.

05

Deleted on request

Ask and we delete your workspace data, and we pass the deletion through to the subprocessors that hold any part of it. Published pages on your own site stay yours and stay published: they are on your infrastructure, not ours.

02 · Least privilege

The narrowest scope that does the job.

Every connection is one you make deliberately during setup, and every one can be revoked from the platform's own settings.

Per-platform scope details
01
Google Search ConsoleQuery and page performance to build the Growth Map, plus index verification after publish
read-only
02
Google Analytics 4Landing-page engagement and conversions, to show whether published work produced outcomes
read-only
03
Your CMSCreating and updating the pages you approve, in the publish state you chose
content:write
04
CRM and billing toolsAttributing leads or revenue to the pages that earned them, only if you connect them
read-only · optional

Google API Services · Limited Use

SearchHandled's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Search Console and Analytics data is used to operate features you asked for, is never sold, is never transferred except as required to provide those features or to comply with law, and is never used to train generalized AI or machine-learning models.

03 · Control & verification

Publishing moves only under your rules.

Auto-publish low-risk work, review everything, or mix the two, with a risk gate and durable publication records underneath either way. Sensitive work and pages with an unsupported claim route to human review, regardless of publish mode.

  • 3publish modes
  • Riskheld for review
  • Readback when supported

04 · Billing custody

The money side, in the open.

Subscriptions, cancellation, and the optional Stripe connection: handled so card data stays with Stripe and the kill switch stays with you.

01

Monthly or annual, cancelled from your side

Choose monthly or annual billing. You can cancel any site at any time from Settings → Billing, which opens the Stripe customer portal. Cancellation takes effect at the end of the current paid period. The site keeps publishing and refreshing until then.

02

Your content never leaves with us

When a subscription ends, nothing is deleted from your CMS. Everything SearchHandled published stays live under your control, and you can export the content queue, publish log, and Growth Map data before closing the workspace.

03

One portal for the paperwork

Invoices, receipts, and payment method changes are all handled in the same portal. If a payment fails, we retry and notify you before any publishing is paused: nothing goes silent.

04

Read-only Stripe, if you connect it

The restricted key you create is read-only, and Stripe enforces its permissions on their side. We can read charges and customers for attribution and cannot move, refund, or modify anything.

05 · Where we stand

Stated plainly, including the gaps.

Responsible disclosure

Reporting a vulnerability

If you find a security issue, report it through the contact form, marked Security and we will acknowledge it. Please give us a reasonable window to fix anything material before disclosing it publicly.

Send the steps to reproduce and what you were able to reach. Please do not include working credentials or customer data in the report itself: describe them and we will arrange a private channel.

Security review

Need the paperwork?

Data processing agreement, subprocessor list, and security questionnaire responses are available on request. We answer with what exists rather than what sounds good.

Ask for the documents

Start with clarity

See the work before you connect anything.

The Growth Map runs on a read-only view of your site and search data. Publishing access comes later, and only when you choose it.

Build my Growth Map