Security
Last updated: 08/16/2026
This page explains, in plain terms, how GEO & SEO Checker protects your account and audit data today — and is honest about what we haven't built yet. If you're evaluating us for your team or agency, this is the real state of things, not a marketing summary.
1. Account Data Isolation
Every table that stores your account data — profile, audit jobs, audit results, and payment records — has PostgreSQL row-level security (RLS) enabled and enforced by the database itself, not just by application code. Policies scope reads and writes to your own account (auth.uid()), so one signed-in user's queries cannot return another user's profile, private audits, or billing history.
2. Authentication
- Sign-in is handled by Supabase Auth, not custom-built session or password code.
- You can sign in with email and password, or with Google.
- We never store your password in our application database — it is hashed and managed entirely by the authentication service, standard practice for modern auth systems.
3. Payment Data
All checkout happens on Stripe's own hosted payment page. We never receive, see, or store your card number, CVC, or full billing details. Stripe passes back only a customer ID, session ID, and payment status, which we use to activate your plan.
4. Encryption in Transit
Our app, API, and database gateway are served over HTTPS only. Plain HTTP requests are redirected to HTTPS, using TLS 1.2/1.3 certificates.
5. Where Audit Data Lives
GEO & SEO Checker runs on infrastructure we operate ourselves — a self-hosted database stack behind our own reverse proxy — rather than a shared third-party platform's default multi-tenant environment. We haven't published the exact physical data center location, and we'd rather say that plainly than claim a region we can't back up.
6. Shared Audit Report Pages
When an audit finishes, it gets a results page you can share by link. Anyone who isn't the owner (and isn't on a paid plan) sees a masked summary — scores and issue titles, not detailed fix instructions — the same limited view a free visitor sees. Today, these results pages don't require a private access token to view; a fully private-by-default option is on our roadmap (see below).
7. Data Retention
We retain account and audit data as long as your account is active, or as needed for the purposes described in our Privacy Policy. We don't currently run an automated deletion job on a fixed schedule — if you want data removed sooner, contact us and we'll handle it manually.
8. What We Don't Have Yet
We'd rather tell you what's missing than let you assume it exists:
- No SOC 2, ISO 27001, or other third-party security certification yet.
- No formal, lawyer-drafted Data Processing Agreement (DPA) template yet — see our Data Processing Terms page for our sub-processor list and how to request a signed DPA.
- No public status or uptime page yet.
- No scheduled, automated data-retention purge job yet.
- No private-by-default toggle for audit reports yet — see section 6 above.
This list will get shorter over time; we'll update this page as each item is built.
9. Security Questions or Reports
If you have a security question, need details for a vendor review, or want to report a vulnerability, contact us directly.
Fastento OU
Laeva 1, Tallinn, 10111, Estonia