Security
Your data, handled carefully.
What we connect to, what we store, what we will never do with your data, and where our compliance posture honestly stands today.
01 · What we hold
What we hold, and what we never do with it.
Five commitments, written as constraints we operate under rather than badges we award ourselves.
The custody recordHeld under your terms
Your accounts stay the source of truth.
Every holding below is revocable from your own Google, CMS, or CRM account without asking us. Published pages live on your infrastructure, not ours.
We never train AI models on your data
Not on your published content, not on your Search Console or Analytics data, not on anything in your CRM. Our model providers operate under commercial terms that prohibit training on customer content, and Google's API policy separately prohibits using Search Console or Analytics data to train generalized models.
Least-privilege access you can revoke
Each connection asks for the narrowest scope that lets it do its job: read-only wherever reading is enough, content-write only where publishing requires it. We never request access to customer records, orders, or billing on your platforms. Every connection is revocable from your own Google, CMS, or CRM account without asking us.
Encrypted in transit and at rest
Traffic runs over TLS, and stored data is encrypted at rest by our hosting provider. We deliberately avoid phrases like bank-level or military-grade encryption: they are marketing terms with no technical definition behind them.
We never sell or share your data
Your content, search data, and performance figures are used to run your account and nothing else. We do not sell data, we do not build an aggregate data product from it, and we do not share it with advertisers.
Deleted on request
Ask and we delete your workspace data, and we pass the deletion through to the subprocessors that hold any part of it. Published pages on your own site stay yours and stay published: they are on your infrastructure, not ours.
02 · Least privilege
The narrowest scope that does the job.
Every connection is one you make deliberately during setup, and every one can be revoked from the platform's own settings.
read-onlyread-onlycontent:writeread-only · optionalGoogle API Services · Limited Use
SearchHandled's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Search Console and Analytics data is used to operate features you asked for, is never sold, is never transferred except as required to provide those features or to comply with law, and is never used to train generalized AI or machine-learning models.
03 · Control & verification
Publishing moves only under your rules.
Auto-publish low-risk work, review everything, or mix the two, with a risk gate and durable publication records underneath either way. Sensitive work and pages with an unsupported claim route to human review, regardless of publish mode.
- 3publish modes
- Riskheld for review
- Readback when supported
04 · Billing custody
The money side, in the open.
Subscriptions, cancellation, and the optional Stripe connection: handled so card data stays with Stripe and the kill switch stays with you.
Monthly or annual, cancelled from your side
Choose monthly or annual billing. You can cancel any site at any time from Settings → Billing, which opens the Stripe customer portal. Cancellation takes effect at the end of the current paid period. The site keeps publishing and refreshing until then.
Your content never leaves with us
When a subscription ends, nothing is deleted from your CMS. Everything SearchHandled published stays live under your control, and you can export the content queue, publish log, and Growth Map data before closing the workspace.
One portal for the paperwork
Invoices, receipts, and payment method changes are all handled in the same portal. If a payment fails, we retry and notify you before any publishing is paused: nothing goes silent.
Read-only Stripe, if you connect it
The restricted key you create is read-only, and Stripe enforces its permissions on their side. We can read charges and customers for attribution and cannot move, refund, or modify anything.
05 · Where we stand
Stated plainly, including the gaps.
Responsible disclosure
Reporting a vulnerability
If you find a security issue, report it through the contact form, marked Security and we will acknowledge it. Please give us a reasonable window to fix anything material before disclosing it publicly.
Send the steps to reproduce and what you were able to reach. Please do not include working credentials or customer data in the report itself: describe them and we will arrange a private channel.
Security review
Need the paperwork?
Data processing agreement, subprocessor list, and security questionnaire responses are available on request. We answer with what exists rather than what sounds good.
Ask for the documentsStart with clarity
See the work before you connect anything.
The Growth Map runs on a read-only view of your site and search data. Publishing access comes later, and only when you choose it.


