Last updated: 2026-10-08. This page exists because **security questions now arrive before the price
discussion. It states what we do, what we hold, and — importantly — what we do not have**.
Read this first: we are a small studio, not an enterprise SaaS company. We have **no SOC 2, no
ISO 27001, and no cyber-insurance certificate**. Saying otherwise would be a lie that a procurement
questionnaire would catch in five minutes. What we do have is set out below, in the same plain terms a
security questionnaire uses.
---
| Question | Answer |
|---|---|
| Who can access customer data? | One person — the operator (the owner of the studio). There is no support team, no contractors, no offshore access. |
| Customer login to our systems? | None. There is no customer portal and no account for you to log into. This removes an entire class of risk. |
| How is the operator authenticated? | SSH key-only (no password login) to the servers, plus 2FA on the hosting, registrar, GitHub and Google accounts. |
| Access to Google data (GSC/GA4)? | Read-only. We request analytics.readonly and Search Console read scope. We cannot change your Google configuration or your site through those credentials. |
| Is access revoked when work ends? | Yes — on request, and access tokens are removed; the Google access is granted by you and can be revoked by you at any time from your own Google account. |
| Question | Answer |
|---|---|
| In transit | HTTPS/TLS for all our endpoints and all connections to your site. |
| At rest | Server disk encryption by the hosting provider (Hostinger / Hetzner). Secrets are stored in an encrypted local credential store, not in code and not in the public repository. |
| Backups | Daily encrypted backup (AES-256, restic) to a second provider and to an offline disk. Backup password is stored separately from the backup. |
This is the honest list — deliberately short.
| Data | Why | Where |
|---|---|---|
| Your domain name | to measure it | our measurement database (SQLite, on our server) |
| Public page data (HTML, canonical, JSON-LD, meta) | to report on-page findings | same database + dated archive files |
| Search Console impressions / clicks / positions | to report search performance | same database |
| Analytics sessions (aggregate) | to report traffic | same database |
| AI assistant answers to our test questions | to measure citation frequency | stored with SHA256 hash, for our own domains and for client domains |
| Your contact address (if you email us) | to reply | your email provider and ours |
What we do NOT hold:
your site — we work with aggregate numbers only.
know whether the page was opened — no IP address is stored by us, no cross-site identifier, no
advertising pixel.
| Question | Answer |
|---|---|
| Are we a processor or controller? | For your Search Console / Analytics data, we act as a processor on your instructions. For our own correspondence, we are a controller. |
| Legal basis | Contract (delivering the service you asked for) and legitimate interest (measuring public web pages, which are public by definition). |
| DPA (Data Processing Agreement) | Available on request — we will sign yours, or provide ours. Send it and it gets signed before work starts. |
| Data location | EU hosting (Hetzner, Finland) for the machine; website hosting with Hostinger. |
| Retention | Measurement data is kept for the duration of the engagement plus 12 months, then deleted. Archive files (dated evidence) are kept because they are the proof of the work; they contain public page data only. You can request deletion in writing and it is done. |
| Sub-processors | Hosting (Hostinger, Hetzner), Google (Search Console / Analytics APIs), the payment provider, and the AI providers used for citation measurement. The list is available on request. |
| International transfers | Google and AI provider calls may leave the EU. These are covered by the providers' standard contractual clauses. |
A DPA and a written sub-processor list are prepared on request. We do not publish a signed DPA because
it has to be signed between two named parties — but the text is ready.
| Question | Answer |
|---|---|
| Who notices an incident? | A daily automated check runs on the machine; if a step fails, it is reported the same day. |
| How fast are you told? | Within 24 hours of us confirming that your data or your site was affected. |
| What happens then? | Written notice with what happened, what data was involved, what was done, and what you should do. No spinning. |
| Do you run third-party audits? | No. We have no SOC 2 or ISO 27001 report. If your procurement requires one, we are not the right vendor yet — and we would rather say so now than after a questionnaire. |
| Question | Answer |
|---|---|
| What if the operator is unavailable? | The machine runs unattended on a daily schedule (05:10) and its output is archived with checksums. Measurement and evidence do not depend on someone being at a desk. |
| What if the hosting fails? | Code and data are in a private git repository plus a daily encrypted backup in a second provider and on an offline disk. Restore is documented. |
| What if you cancel? | Your dated evidence files (archives with checksums) remain valid — they are plain files you already have. We do not hold your data hostage. |
For security questions, questionnaires, a DPA, or a sub-processor list: send the request in writing
(email or the public issue tracker). You will get a written answer with the specifics, not a marketing page.
security.txt: published at /.well-known/security.txt with the contact route for vulnerability
reports.
---
1. One person has access, there is no customer login, and Google access is read-only.
2. We hold almost nothing: your domain, public page data, aggregate Google numbers — **no visitor
personal data, no cookies, no card data**.
3. We have no SOC 2 / ISO 27001. We say that here instead of claiming it. If you need those, we will
tell you we are not ready rather than waste your procurement cycle.
Start async — no calls, no meetings. Write the domain and what you want measured; you get a written answer with the artifacts.