Security and privacy
How Metric Vault protects your account, what data it stores and for how long, who else touches it, and how to exercise your data rights.
Last updated 2026-08-06
Summary#
This category answers two questions. What protects your account and the work inside it, and what happens to the information you give us. Everything here is written against what the platform actually does today, so you can rely on it in a security review, a procurement questionnaire or a conversation with your own compliance team.
Overview#
Metric Vault holds business intelligence: the domains you analyze, the competitors you watch, the keywords you are chasing and the reports you build for clients. The protections around that fall into two groups, and this category is split the same way.
Platform security is about access: who can sign in, what the server checks before it does anything on your behalf, and how programmatic access is handled.
Privacy and data is about information: what is stored, where it lives, how long it stays, who else sees it, and how you get it back or have it removed.
Start here#
- How we protect your account — the plain-language account of what protects your account: managed sign-in, encrypted transport, server-side entitlement checks, account isolation and Stripe-handled payments. Read this first.
- Security best practices for your team — the practical checklist for a team: password hygiene, seat reviews, share-link discipline and key rotation.
- Account security — the same subject from the account screen's point of view, including what is not available today.
What we store and for how long#
- What data we store — every category of stored data, where it is held and why, including what is kept in your browser rather than on our servers.
- Data retention and deletion — retention in practice: the automatic 90-day purge of saved work, what stays until you delete it, and what happens when an account is closed.
- Subprocessors and data flow — every outside service involved in delivering the platform and exactly what each one receives.
Compliance and your rights#
- GDPR and compliance — the commitments we make under GDPR, UK GDPR and CCPA, how international transfers are handled, and the exact route for an access, correction, portability or deletion request.
- Deleting your account — how to close an account and what goes with it.
- Exporting your data — what you can export today, and how to request a full copy of your data.
For engineers and administrators#
These pages are written for internal readers and are precise about mechanism.
- Authorization model — every authorization gate, what it protects, and how each behaves when a dependency is unavailable.
- API key security — how API keys are issued, stored and revoked, and the operational handling that follows.
- Security headers and CSP — the complete response-header inventory, including what is not set.
- Authentication and authorization flow — the request-level walkthrough of authentication and authorization.
Reporting a security problem#
If you have found a vulnerability, write to hello@metricvaultai.com with the subject line Responsible Disclosure - [Brief Description]. Include what you found, how to reproduce it and the impact you think it has. We acknowledge reports within two business days and ask that you give us a reasonable opportunity to investigate before disclosing publicly.
For anything else, including a privacy rights request, Contacting support lists the contact routes and what to include.
See also
Was this article helpful?
Thanks — feedback noted for the docs team.