Trust

Security

How we protect your data and how our crawler behaves. We state our real posture, including what is still in progress, rather than reassuring boilerplate.

Last updated · Questions: support@seoforaiagents.com

Our security posture in one paragraph

SEO for AI Agents is operated by Own The Climb. We are a small, security-conscious team building a tool that crawls public web pages and stores audit results. We do not handle payment card data directly, we do not knowingly process special-category personal data, and we crawl politely and identifiably. This page describes, in plain language, exactly how we protect data and how our crawler behaves. We would rather state our real posture, including what is still in progress, than publish reassuring boilerplate.

Encryption in transit and at rest

All traffic to and from our application is served over HTTPS with TLS, with HTTP redirected to HTTPS and HSTS enabled. Data stored in our database is encrypted at rest by our database provider. Secrets and service credentials are stored in environment configuration, never in source control, and the database service-role key never reaches the browser.

Data retention

Our retention is deliberately lean. We keep only what the product needs to function:

  • Audit results (scores, findings, and the crawled page metadata they are derived from) are retained for the lifetime of the associated account. Anonymous public audits are kept until deleted on request, or until the account for the email that ran them is deleted. They do not expire automatically today.
  • Account data (email, organization, preferences) is retained while the account is active. Deleting your account in settings removes it right away; a deletion request by email is completed within 30 days. Stripe keeps its own billing records as the law requires.
  • Email addresses captured from the free tools are retained until the person unsubscribes or requests deletion.
  • Error events are kept for debugging, with personal data scrubbed from error payloads before storage and the user link removed when an account is deleted. Rate-limit counters are purged after 3 days and job logs after 7 days.

You can request deletion of your data at any time by emailing support@seoforaiagents.com. Anonymous public reports can be removed on request to the same address.

How we crawl the web

Our audit fetches public web pages to analyze them. We crawl the way we would want our own site crawled:

  • We honor robots.txt. If a path disallows our crawler, we do not fetch it. We do not bypass robots rules and we do not crawl content behind authentication.
  • We rate-limit per host. By default we make at most one request per second to a given host, and never more than five, so we do not degrade the sites we audit.
  • We identify ourselves. Our crawler sends a descriptive User-Agent with a contact URL, so any site owner can recognize our traffic and reach us.
  • We do not impersonate other crawlers. We never claim to be Googlebot or any other agent.
  • We crawl only what we are asked to. An audit fetches the requested URL and a bounded set of pages linked from it, within the configured depth.

The full crawl-behavior policy and current User-Agent string are documented on our bot policy page.

Sub-processors

We use the following third-party services to operate the product. We keep this list current and will update it before adding a new sub-processor that handles personal data.

Sub-processorPurposeRegion
SupabaseApplication database (Postgres) and authenticationUnited States
VercelApplication hosting, serverless functions, scheduled jobs, headless audit sandboxUnited States, global edge
Vercel AI GatewayRoutes requests to the AI model providers belowUnited States, global edge
AI model providers: Google (Gemini, through the AI Gateway or Vertex AI), OpenAI, Anthropic, Perplexity, xAIWriting findings and recommendations, safety review, AI answer measurement, and drafting support repliesVaries by provider
SerperGoogle results pages for AI Overview measurement (search queries only)Varies by provider
StripePayments, subscriptions, invoices, and the billing portalUnited States
ResendSending transactional and lifecycle email, and receiving support emailUnited States
CloudflareDNS and bot protection (Turnstile)Global edge
UpstashRate-limiting counters (Redis)United States

GDPR and data processing agreement

We support the rights granted by the GDPR and comparable regimes: access, rectification, erasure, portability, and objection. A Data Processing Agreement (DPA) is available on request for customers who need one for their compliance program. Email support@seoforaiagents.com and we will send the current template.

We do not sell personal data, and we do not use customer audit data to train AI models. Where an audit uses an AI model, the page content it needs is sent to that model provider for that audit and processed under the provider’s API terms.

Breach disclosure

If we become aware of a security breach affecting personal data, we will investigate promptly, take steps to contain it, and notify affected customers without undue delay and in any case within 72 hours of confirming a reportable breach, consistent with GDPR expectations. Notifications will describe what happened, the data involved, and the steps we are taking.

To report a suspected vulnerability or security issue, email support@seoforaiagents.com with the details. We appreciate responsible disclosure and will respond.

Access control and data isolation

Customer data is isolated per organization at the database level using row-level security, so one tenant cannot read another tenant's audits. Administrative access to production is limited to the operating team and protected by the access controls of our providers. Authentication uses magic links and OAuth; we do not store passwords by default.

SOC 2 and compliance roadmap

We will be direct about this: we do not currently hold a SOC 2 Type II report, and we will not claim one we do not have. SOC 2 readiness work is on our roadmap as we grow into the mid-market and agency segments. If your procurement requires a specific attestation or a security questionnaire, email support@seoforaiagents.com and we will tell you honestly where we are and what we can provide today, including the DPA and this documentation.