Trust
Security
How we protect your data and how our crawler behaves. We state our real posture, including what is still in progress, rather than reassuring boilerplate.
Last updated · Questions: support@seoforaiagents.com
Our security posture in one paragraph
SEO for AI Agents is operated by Own The Climb. We are a small, security-conscious team building a tool that crawls public web pages and stores audit results. We do not handle payment card data directly, we do not knowingly process special-category personal data, and we crawl politely and identifiably. This page describes, in plain language, exactly how we protect data and how our crawler behaves. We would rather state our real posture, including what is still in progress, than publish reassuring boilerplate.
Encryption in transit and at rest
All traffic to and from our application is served over HTTPS with TLS, with HTTP redirected to HTTPS and HSTS enabled. Data stored in our database is encrypted at rest by our database provider. Secrets and service credentials are stored in environment configuration, never in source control, and the database service-role key never reaches the browser.
Data retention
Our retention is deliberately lean. We keep only what the product needs to function:
- Audit results (scores, findings, and the crawled page metadata they are derived from) are retained for the lifetime of the associated account. Anonymous public audits are kept until deleted on request, or until the account for the email that ran them is deleted. They do not expire automatically today.
- Account data (email, organization, preferences) is retained while the account is active. Deleting your account in settings removes it right away; a deletion request by email is completed within 30 days. Stripe keeps its own billing records as the law requires.
- Email addresses captured from the free tools are retained until the person unsubscribes or requests deletion.
- Error events are kept for debugging, with personal data scrubbed from error payloads before storage and the user link removed when an account is deleted. Rate-limit counters are purged after 3 days and job logs after 7 days.
You can request deletion of your data at any time by emailing support@seoforaiagents.com. Anonymous public reports can be removed on request to the same address.
How we crawl the web
Our audit fetches public web pages to analyze them. We crawl the way we would want our own site crawled:
- We honor robots.txt. If a path disallows our crawler, we do not fetch it. We do not bypass robots rules and we do not crawl content behind authentication.
- We rate-limit per host. By default we make at most one request per second to a given host, and never more than five, so we do not degrade the sites we audit.
- We identify ourselves. Our crawler sends a descriptive User-Agent with a contact URL, so any site owner can recognize our traffic and reach us.
- We do not impersonate other crawlers. We never claim to be Googlebot or any other agent.
- We crawl only what we are asked to. An audit fetches the requested URL and a bounded set of pages linked from it, within the configured depth.
The full crawl-behavior policy and current User-Agent string are documented on our bot policy page.
Sub-processors
We use the following third-party services to operate the product. We keep this list current and will update it before adding a new sub-processor that handles personal data.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Application database (Postgres) and authentication | United States |
| Vercel | Application hosting, serverless functions, scheduled jobs, headless audit sandbox | United States, global edge |
| Vercel AI Gateway | Routes requests to the AI model providers below | United States, global edge |
| AI model providers: Google (Gemini, through the AI Gateway or Vertex AI), OpenAI, Anthropic, Perplexity, xAI | Writing findings and recommendations, safety review, AI answer measurement, and drafting support replies | Varies by provider |
| Serper | Google results pages for AI Overview measurement (search queries only) | Varies by provider |
| Stripe | Payments, subscriptions, invoices, and the billing portal | United States |
| Resend | Sending transactional and lifecycle email, and receiving support email | United States |
| Cloudflare | DNS and bot protection (Turnstile) | Global edge |
| Upstash | Rate-limiting counters (Redis) | United States |
GDPR and data processing agreement
We support the rights granted by the GDPR and comparable regimes: access, rectification, erasure, portability, and objection. A Data Processing Agreement (DPA) is available on request for customers who need one for their compliance program. Email support@seoforaiagents.com and we will send the current template.
We do not sell personal data, and we do not use customer audit data to train AI models. Where an audit uses an AI model, the page content it needs is sent to that model provider for that audit and processed under the provider’s API terms.
Breach disclosure
If we become aware of a security breach affecting personal data, we will investigate promptly, take steps to contain it, and notify affected customers without undue delay and in any case within 72 hours of confirming a reportable breach, consistent with GDPR expectations. Notifications will describe what happened, the data involved, and the steps we are taking.
To report a suspected vulnerability or security issue, email support@seoforaiagents.com with the details. We appreciate responsible disclosure and will respond.
Access control and data isolation
Customer data is isolated per organization at the database level using row-level security, so one tenant cannot read another tenant's audits. Administrative access to production is limited to the operating team and protected by the access controls of our providers. Authentication uses magic links and OAuth; we do not store passwords by default.
SOC 2 and compliance roadmap
We will be direct about this: we do not currently hold a SOC 2 Type II report, and we will not claim one we do not have. SOC 2 readiness work is on our roadmap as we grow into the mid-market and agency segments. If your procurement requires a specific attestation or a security questionnaire, email support@seoforaiagents.com and we will tell you honestly where we are and what we can provide today, including the DPA and this documentation.