Check my visibility

Trust · Security

Security

How we protect your data and run the Service. We describe our current posture plainly — what we do today, and what is on the roadmap — without claiming certifications we do not yet hold.

Version
1.0
Updated
23 Jun 2026
Contact
security@searchdaddy.com
Status
Draft · pending review

Our approach

Security is built into how we run SearchDaddy, Inc., not bolted on. We collect only the data we need to deliver the Service, limit who can access it, encrypt it in transit, and rely on reputable infrastructure and providers. As we grow, our program will mature toward formal third-party attestation. This page reflects our actual current state.

Straight talkWe do not currently hold a SOC 2, ISO 27001, or HIPAA attestation. We will say so clearly, and will not display a compliance badge, until an independent report exists. If a vendor questionnaire requires one, talk to us about timing.

Infrastructure

The Service runs on established cloud infrastructure with managed networking, a PostgreSQL database, and Redis for queues and caching. Background processing is handled by a managed worker layer. Production is separated from development, and access to production systems is restricted to authorized personnel.

Encryption

Traffic to and from the Service is encrypted in transit using TLS. Data is encrypted at rest where supported by our infrastructure and providers. Secrets and credentials are stored using secure configuration, never in source control.

Access control

We apply least-privilege access: people and systems get only the access they need. Authentication is enforced for application access, and sessions use scoped cookies at the SearchDaddy, Inc. domain. Administrative access is limited and separated from standard user access. Personnel and contractors are bound by confidentiality obligations.

Application security

We follow secure development practices, including code review, automated formatting and testing in our pipeline, and dependency management. The application is built on a maintained framework and kept current with security updates. We design APIs and tokens to limit exposure of sensitive data.

Providers & AI engines

We rely on vetted sub-processors for payments, email, error monitoring, search data, and AI-engine queries. Each maintains its own security program. The current list and their functions are published in our Data Processing Addendum. When we query AI engines, we send only the business information needed for the analysis and design prompts to avoid unnecessary personal data.

Data handling

We collect the minimum data needed to run audits, monitoring, and Done-for-You Services. Customer Data is logically separated per account. We retain data to provide historical trends and meet legal obligations, and delete or de-identify it when no longer needed. Customers can export data and request deletion as described in our Privacy Policy and DPA.

Monitoring & response

We log application activity and use error-monitoring and alerting to detect issues. If we become aware of a security incident affecting your data, we will investigate, contain it, and notify affected customers without undue delay, consistent with our DPA and applicable law.

Reporting an issue

If you believe you have found a vulnerability, please email security@searchdaddy.com with details and steps to reproduce. Please give us a reasonable opportunity to address the issue before public disclosure, and do not access or modify data that is not yours. We appreciate responsible disclosure and will acknowledge legitimate reports.

Compliance roadmap

We comply with applicable privacy law, including the CCPA/CPRA, and offer a DPA for business customers. Formal security attestations (such as SOC 2 Type II) are planned as the business scales. We will update this page and publish reports when they are available, and not before.

Contact

Security questions: security@searchdaddy.com. Privacy requests: privacy@searchdaddy.com.

↑ Back to top · Version 1.0 · Updated 23 Jun 2026