Help / Security & compliance / Security & privacy

Security & privacy

For everyone (and their lawyers) · ~4 min read · Last reviewed 22 July 2026

The short version for your due-diligence checklist. Every claim below links to the document that actually governs it — this page summarises, the documents decide.

Where and how your data is kept

  • Your data is stored and processed in Finland (EU).
  • Google Search Console tokens are stored encrypted at the database level. The Search Console scope is read-only — SeoKestrel cannot change anything on your site or in your Search Console.
  • New passwords are screened against known breach datasets, and repeated failed sign-ins lock the account temporarily.
  • Administrative actions are recorded in an audit log (Settings → Audit log, visible to admins).
  • Your consent choices (terms, privacy, marketing, cookies) are recorded with their full history and manageable under Settings → Privacy.
  • Data-subject rights — export and deletion — are handled via Settings → Privacy / Data requests.
  • Third-party processors and their regions are listed publicly on the sub-processors page.

Operational security

  • Security incidents are tracked in a dedicated incident register (Settings → Incidents, admin-only) through detection → containment → notification, in line with our NIS2 obligations — significant incidents are reported to the national authority within 24 hours.
  • Personal API keys (Settings → API keys) are shown once at creation, stored only as a hash, and revocable at any time. Treat them like passwords; revoke immediately if one leaks.
  • Crawl data is supplied by SeoSwift, a separate product, over a server-to-server channel: only crawl-derived results cross that boundary. Your Google credentials are never shared with SeoSwift.

The documents

Good to know

If your client’s procurement team sends a security questionnaire, the five links above answer most of it. For anything they cover differently, the linked documents — not this summary — are authoritative.

FAQ

Is my data used to train AI models?
See the Privacy Policy for the authoritative answer on data use — the summary here is deliberately not the contract.
How do I delete my account and data?
Settings → Privacy → submit a data request. Timelines and scope are defined in the Privacy Policy.
Who can see the audit log?
Admins — and future-you during an incident review, gratefully.