Trust & Security

Trust Center

How we keep your account secure and make working with us easy for enterprise teams. AuthoritySpecialist SEO Solutions OÜ is an established Estonia (EU) company.

Security practices

Encryption

TLS in transit; encryption at rest on data stores that support it.

Access control

Role-based access, least privilege, and audit logging of account actions.

Network protection

WAF and CDN, rate limiting, and continuous monitoring.

Resilience

Managed backups and a documented recovery process.

Your account & your data

We work with your public marketing data (your website, search and analytics performance) — not your customers' private records. You can export or delete your account data at any time from your dashboard, and we never sell personal data. Analytics on our own site load only after consent.

Documents

Contact

Security or account questions: security@authorityspecialist.com. Enterprise contracting (MSA, NDA): legal@authorityspecialist.com.

Review the relationship

Evaluate trust through scope, evidence, ownership, and governing documents

Use this Trust Center as a starting point for reviewing security practices, data handling, legal terms, service responsibilities, and the people accountable for answering questions. The purpose is to help a reviewer determine what must be checked for the relationship under consideration, which evidence is relevant, and where an authoritative answer belongs. A public overview should not be treated as a substitute for customer-specific due diligence, a completed security review, executed contractual terms, current technical evidence, or configuration details that only apply to a particular engagement.

Begin by defining the actual scope before assessing individual controls or statements. Identify the services being considered, the information they receive, the systems and people that may access that information, the integrations involved, the applicable regions, the retention and deletion expectations, and the business process that depends on the service. Distinguish public website content and ordinary marketing information from account information, credentials, customer records, confidential material, and regulated content. Then request evidence that corresponds to that scope. A familiar control label or broad security statement is not enough when the decision depends on how a specific service, data flow, access path, or responsibility is handled.

Map each open question to an accountable owner and a controlling source. Legal reviewers should identify the agreement, privacy terms, data terms, and other governing documents that apply to the proposed relationship. Security reviewers should record control questions, evidence reviewed, exceptions, and residual risk rather than assuming that a public summary resolves the matter. Service owners should confirm operational expectations for access, support, deletion, continuity, changes, and exit. Repeat the review when the scope materially changes, including changes to integrations, data categories, access, regions, subprocessors, criticality, or governing terms. Do not infer a certification, guarantee, data location, recovery commitment, contractual remedy, or other obligation unless the current authoritative source for the applicable scope states it.

Trust questions

Questions to resolve before relying on a Trust Center

Does a Trust Center prove that a service is certified or secure?
No. A Trust Center can summarize practices, explain review boundaries, and direct readers to relevant documents or contacts, but it is not itself proof of a certification or a complete security conclusion. Where a certification, report, control, scope, or validity period matters to the decision, verify the current evidence through the appropriate review process and confirm that it applies to the service being assessed.
What should be defined before reviewing vendor risk?
Define the service in scope, the data categories involved, how data enters and leaves the service, who or what can access it, the integrations and user groups involved, the applicable regions, retention expectations, business criticality, and relevant legal or regulatory requirements. These boundaries determine which security questions, privacy considerations, operational controls, and contractual terms are actually relevant.
What should a reviewer do when public, technical, or contractual statements conflict?
Record the conflict, identify the scope of each statement, and ask the accountable security, privacy, legal, or service owner for the current authoritative answer. Do not choose the statement that is easiest to accept, combine statements that apply to different scopes, or treat an older summary as controlling when a current governing source is required.
When should a trust review be performed again?
Repeat the review when the relationship changes in a way that could affect risk or obligations, such as a material change to service scope, integrations, data categories, regions, access, subprocessors, business criticality, or governing terms. Also follow the periodic review interval required by the reviewing organization's own risk program rather than assuming that an earlier approval remains sufficient indefinitely.
What records should remain after the review is approved?
Retain the approved scope, the evidence references used for the decision, material findings, exceptions, accountable owners, review status, renewal or reassessment triggers, governing contractual documents, and any required remediation or follow-up. Store only what is necessary for the review record, and avoid copying secrets, credentials, sensitive technical evidence, or restricted material into systems that are more broadly accessible than the source.