Skip to content
Metric VaultHelp Center
Open app

How we protect your account

The protections actually in place around a Metric Vault account: managed sign-in, encrypted transport, server-side entitlement checks, account scoping and Stripe-handled payments.

Last updated 2026-08-06

Summary#

Metric Vault holds work that matters commercially: the domains you analyze, the competitors you track, and the reports you hand to clients. This page sets out what protects that work today, in plain terms, and is honest about the controls that do not exist yet. A vague security page is worse than none, because it invites you to assume protections you do not have.

Purpose#

You need three things from a security page. A clear statement of what is in place, so you can complete a review or answer your own compliance team. A clear statement of what is not, so you can compensate for it. And a route to reach us when something looks wrong. This page gives all three.

The formal, contractual version of these commitments is published on the Security, Privacy and GDPR pages at metricvaultai.com. This article explains what those commitments mean in practice inside the product.

Overview#

Six things stand between your work and someone who should not have it.

Sign-in is handled by a dedicated identity service. Your password is held by that service, not inside the Metric Vault application. Nobody at Metric Vault can read it or set it. Google sign-in is also available, so you can rely on your existing account security there instead.

An email address has to be confirmed before it counts as an identity. The server checks confirmation itself on every verification, so an address someone merely typed into a form is never treated as an account.

Everything travels over HTTPS. Traffic between your browser, the Chrome extension or your own scripts and Metric Vault is encrypted in transit. Plain HTTP connections to the platform are not served.

Entitlement is decided on the server, on every request. Whether you can run a tool, spend a credit, invite a teammate, reach another workspace or use a premium feature is checked server-side each time. Hiding a control in the interface is never the mechanism.

Payments never touch our systems. Checkout and the billing portal are operated by Stripe. Card numbers are not stored on, processed by, or transmitted through Metric Vault.

Work is scoped to the account that produced it. Saved results, monitored URLs, alerts, schedules and branding belong to a workspace, and reaching a workspace you do not own requires an invitation you have accepted, verified against the membership record on the server.

How it works#

Sign-in and sessions#

You sign in with an email address and password, or with Continue with Google. Failed sign-ins all return the same message, Invalid email or password, so the error text cannot be used to work out which addresses have accounts.

Signing in gives your browser a session that renews itself while you work. Each browser holds its own, so signing in on a laptop does not sign you in on a phone. Log Out ends the session in the browser you are using; Log Out All on the Account screen ends every session for the account, on every device, at once. Sessions and signing out covers this in detail, and Changing your password covers setting or resetting a password.

What the server checks before it acts#

CheckWhat it preventsWhat you see if it stops you
Signed inAnonymous use of metered toolsPlease sign in to run this.
Plan tierUse of a feature above your planThis feature requires the <Tier> plan. Your account is on <Plan>. Upgrade to unlock it.
Free-plan scopePaid tools running on a Free accountThis tool needs a paid plan. Free includes the 10 technical SEO tools; upgrade to Pro to unlock the rest.
Monthly credit quotaSpending beyond the plan's allowanceA message naming your plan, the credits used, the cap and the reset date
Hourly fair-use limitAutomated abuse of the light toolsHourly fair-use limit reached (100 light-tool calls/hour). …
Account statusA suspended account spending creditsThis account is suspended. Please contact support.
Workspace membershipReaching a workspace you were never invited toYou stay in your own workspace
Target addressTools being pointed at private or internal network addressesThat host is not allowed

Two of these behave in your favour rather than the system's convenience. The plan and quota checks refuse rather than guess: if your plan or usage cannot be confirmed at that moment, the request is declined with a temporarily unavailable, please retry message instead of being waved through. You may occasionally have to retry. You will not have someone else's entitlement applied to your account.

The last row is worth calling out because it is invisible until you hit it. Any tool that fetches a URL you supply, including the site auditors and the webhook destinations on the competitor monitor, refuses private, loopback, link-local and cloud-metadata addresses in every notation they can be written in. That stops the platform being used to reach something on a private network.

Where your data lives#

Metric Vault runs on managed cloud infrastructure in the United States: the application, its database and its object storage. Identity is held by a separate managed authentication service. Payments and card data live with Stripe. What data we store lists every category of stored data and where it sits, and Subprocessors and data flow lists every outside service involved and exactly what each one receives.

Our formal commitments on encryption at rest, encrypted backups and physical infrastructure security are set out on the Security page at metricvaultai.com/legal/security.

Account isolation and staff access#

Your analyses, saved work and reports are visible to you and to the people you have invited into your workspace. They are not shown to other customers, and they are not used to build a product other customers can query.

One clarification, because it comes up in reviews. Metric Vault keeps a shared cache of provider data in front of the paid search-data providers, so a repeat lookup of the same domain or keyword does not re-bill the provider. That cache is keyed by the tool and the query only. It holds third-party search data about a public domain, never your account, your reports or anything identifying who ran the lookup. Result caching and freshness explains how it affects your results and your credits.

Metric Vault staff may access account data to investigate a support request you have raised, to diagnose a technical problem, or where a legal obligation requires it. Administrative changes made to an account, such as a plan change, a usage reset or a suspension, are written to an internal audit record with the actor, the action, the target and the time.

Payments#

Card details are never entered into Metric Vault. Both the upgrade flow and Manage Billing hand you to Stripe, which is PCI-DSS Level 1 certified. The app says so before it sends you there: Payment is handled by Stripe. We never see or store your card details. Incoming billing events from Stripe are signature-verified before they can change anything about your plan, and an unverifiable event is rejected rather than trusted. See Subscribing and checkout and Managing billing in the customer portal.

Programmatic access#

API keys are an Enterprise capability. A key is generated from a cryptographic random source, shown once at creation, and revocable at any time. Every call re-checks the owning account's current plan, so a key stops working the moment the account no longer qualifies. There is a hard cap of five active keys per account, and keys carry no scopes: treat one as a production secret with full access to the analysis endpoint and the account's credits. See API keys and API key security.

Sharing is an explicit act#

A share link is public by design. The dialog that creates it says so, and anyone holding the URL can open the report without signing in. You choose whether it expires. Treat a share URL as published, and use an export for anything confidential. See Sharing a result by link and Exporting results.

The Chrome extension#

The extension asks for the minimum it needs. It reads the address of the tab you are on only when you click it and start an analysis. It does not watch your browsing, and it does not read cookies, form data or history from any site. See The Chrome extension.

Availability and status#

Platform availability is monitored continuously through Uptime Robot, and the live status page is at stats.uptimerobot.com. We target 99.9% monthly uptime on paid plans. If a tool is failing for you, 503 and service-unavailable errors is the fastest way to tell an outage from a configuration problem.

What is not available today#

Being straight here matters more than sounding complete.

Not availableWhat to do instead
Two-factor authentication. The Security tile reports this honestly as 2FA offUse a long unique password from a password manager, or sign in with Google and secure that account with two-factor there
Single sign-on or SAMLEmail and password, or Google
A list of active devices, and signing out one of themLog Out All, which ends every session at once
An administrator action that force-signs-out a customerThe account holder runs Log Out All
A customer-facing log of sign-ins and password changesNothing. There is no customer-facing audit log; support can check the admin audit log on request
IP allowlisting, or restricting an API key to one address or domainProtect the key as a production secret and rotate it. See API key security
A self-service delete button that erases the account immediatelyDeletion is a request handled by support. See Deleting your account

Reporting a security problem#

Write to hello@metricvaultai.com with the subject line Responsible Disclosure - [Brief Description]. Include the nature of the issue, the steps to reproduce it, and the impact you believe it has. We acknowledge reports within two business days and ask that you give us a reasonable opportunity to investigate before disclosing publicly. Responsible research is welcome and contributors are credited where permitted.

If you think an account has been compromised, run Log Out All, change the password, revoke any API keys, and then contact support. Contacting support lists the routes.

See also

Was this article helpful?