Security, data processing and service levels
Last updated: 12 August 2026
Researched, written and published by Ronnie Huss, founder of SearchScore.
This page is written for the person doing procurement review. It states what we actually do, including where we fall short of what a larger vendor would offer, because a security page that only lists strengths tells you nothing you can rely on.
1. Who processes your data
SearchScore is operated by Product Specialists LTD, registered in England and Wales. For UK GDPR purposes we act as a processor for the account data you give us, and as a controller for our own business records.
Data protection contact: hello@searchscore.io
2. Where it lives
Application servers and databases are hosted on dedicated infrastructure with IONOS SE, in London, United Kingdom. Your account data does not leave the UK except where a sub-processor below necessarily receives it.
The public website and API sit behind Cloudflare, which terminates TLS. All traffic to
searchscore.io and api.searchscore.io is HTTPS only.
3. What we hold about you
For a Tracker subscription:
- Your email address and the domain you track
- The business details you enter: brand name, location, business type, description, and the competitor names and questions you configure
- Every scan result: which engine answered which question, whether it cited you, the source URLs it returned, and the answer text
- Billing references from Stripe (a customer and subscription identifier)
- If you connect Search Console, the property name and the search queries we read from it
We never receive or store card details. Payment is handled entirely by Stripe; we hold only their identifiers. We do not store passwords: sign-in is by emailed link.
4. Sub-processors
These are the third parties that necessarily see some part of your data, and why:
- OpenRouter: routes the questions we ask to the six AI engines. Receives the question text and your brand name, because that is the measurement.
- Stripe: payments. Receives your email and billing details directly.
- Brevo: transactional email. Receives your email address and message content.
- Google: only if you connect Search Console or Analytics, and only to read.
- DataForSEO: search-result data for the pages we audit.
- Cloudflare: content delivery and TLS termination.
We will give 30 days' notice before adding a sub-processor that handles account data.
5. Retention
- Scan history: kept for the life of the subscription, because the product is a trend over time and deleting it would remove what you pay for.
- Shared report links: 12 months, then purged automatically.
- Email send records: kept so you can see what we sent you.
- On cancellation: tell us and we delete your account data within 30 days. We do not delete automatically on cancellation, because reactivation is common and silent deletion of a trend somebody spent months building is worse than holding it.
6. Access and controls
- Administrative access to servers is restricted to key-based SSH; password login is disabled.
- Sign-in to the Tracker is by time-limited emailed link. There are no passwords to leak.
- API keys are stored only as a SHA-256 hash. We cannot show you a key again after it is created, and neither can anyone who reaches the database.
- Outbound webhooks are signed with HMAC-SHA256 so you can verify a request came from us.
- Databases are backed up nightly and held on the same infrastructure.
Where we fall short, stated plainly. Database files are not separately encrypted at rest; they sit on a dedicated host with restricted access. We hold no card data, no passwords, and no special-category personal data, so the material at risk is your business configuration and your scan history. We are a small team and do not hold SOC 2 or ISO 27001. If either is a hard requirement for you, we would rather tell you now than during onboarding.
7. Service level
For Enterprise subscriptions we commit to 99.5% monthly availability of the dashboard and API, measured per calendar month and excluding scheduled maintenance announced at least 48 hours ahead.
If we miss it, you may claim a service credit against the following month: 10% for availability below 99.5%, 25% below 99%, and 50% below 95%.
What the commitment deliberately does not cover. Scan delivery timing is excluded. A scan asks six third-party AI engines, and when one of them is degraded or rate limiting, the delay is theirs and we cannot honestly promise around it. We report per-engine failures rather than hiding them in an average, so you can always see which engine did not answer and when.
8. Incidents
If we become aware of a personal data breach affecting your account we will notify you without undue delay and in any event within 72 hours of becoming aware, with what we know, what we are doing, and what you may need to do.
9. Your rights, and getting your data out
You can export everything we hold about your scans at any time, without asking us: the cell-level export gives one row per question, engine and scan, in CSV or JSON. See the API guide.
For access, correction, deletion or portability requests, email hello@searchscore.io. We respond within 30 days.
A signable data processing agreement is available on request for Scale and Enterprise accounts.