We take the security of your data and your account seriously. This page explains what we do to protect MetricVault AI, your information, and the platform you rely on every day.
Security
MetricVault AI · metricvaultai.com
Effective Date: July 3, 2026 | Last Updated: July 15, 2026
1. Our Commitment to Security
MetricVault AI handles sensitive business intelligence: domain data, competitor analyses, keyword strategies, and brand visibility metrics that matter to your business. We treat that responsibility seriously. Security is not an afterthought here; it is built into how we architect, deploy, and maintain the Platform.
This Security page is meant to give you a clear, honest picture of the measures we have in place. We do not list security theater. We describe what we actually do.
2. Infrastructure and Hosting
2.1 Cloud Infrastructure
MetricVault AI is hosted on cloud infrastructure in the United States. We use established, enterprise-grade cloud providers with robust physical security, redundancy, and compliance certifications. Our infrastructure is designed to isolate user data and provide high availability.
2.2 Data Encryption in Transit
All data exchanged between your browser or application and MetricVault AI servers is encrypted using TLS 1.2 or higher (HTTPS). This applies to the web dashboard, API endpoints, and any data transmitted via the Chrome extension. We do not permit unencrypted HTTP connections to the Platform.
2.3 Data Encryption at Rest
Sensitive data, including account credentials and personal information, is encrypted at rest using AES-256 or equivalent encryption standards. Database backups are also encrypted.
2.4 Uptime and Availability
We monitor platform availability in real time through Uptime Robot. Current platform status is always available at stats.uptimerobot.com. We aim for 99.9% monthly uptime on paid plans.
Planned maintenance windows are scheduled during low-traffic hours and communicated in advance where possible.
3. Authentication and Access Control
3.1 Password Security
User passwords are never stored in plain text. We use industry-standard hashing algorithms (bcrypt or equivalent) with salt to store password hashes. This means that even in the event of a database breach, your actual password is not exposed.
We recommend using a strong, unique password for your MetricVault AI account. You can reset your password at any time from the login page.
3.2 Session Management
Sessions are managed using secure, HTTP-only cookies with appropriate expiration policies. Session tokens are invalidated on logout. We recommend logging out from shared or public devices after use.
3.3 API Key Security
Enterprise plan users can generate API keys from the dashboard. API keys grant programmatic access to the Platform and should be treated like passwords. Best practices:
- Never expose API keys in public code repositories, client-side JavaScript, or publicly accessible files
- Rotate API keys immediately if you suspect a key has been compromised.
- Use different keys for different applications or environments when possible.
- Revoke unused keys from the API management section of your dashboard.
If you believe an API key has been compromised, revoke it from your dashboard immediately and contact us at hello@metricvaultai.com.
3.4 Team Access Controls
For multi-seat plans (Pro, Agency, Enterprise), team members are granted access through your shared workspace. As the account owner, you can:
- Add and remove team members at any time.
- Manage seat assignments from the account dashboard.
- Contact us to adjust permissions or roles if your plan supports it.
We recommend removing team members promptly when they leave your organization.
4. Payment Security
MetricVault AI does not store, process, or transmit your credit card numbers or full payment details. All payment processing is managed by Stripe, Inc., a Payment Card Industry Data Security Standard (PCI-DSS) Level 1 certified service provider, the highest level of PCI certification available.
What Stripe stores on our behalf:
- A tokenized representation of your payment method
- Billing address (used for fraud prevention)
- Transaction history and amounts
You can review Stripe's security practices at stripe.com/security.
5. Application Security
5.1 Secure Development Practices
Our development team follows security-conscious coding practices, including:
- Input validation and output encoding to prevent injection attacks.
- Parameterized queries to protect against SQL injection.
- CSRF (Cross-Site Request Forgery) protection on all state-changing operations
- Content Security Policy (CSP) headers to mitigate cross-site scripting (XSS) risks.
- Regular dependency audits to identify and patch known vulnerabilities in third-party libraries.
5.2 Security Reviews
We conduct regular internal security reviews of our codebase and infrastructure. As the platform matures, we are committed to expanding our security testing program, including third-party penetration testing.
5.3 Vulnerability Disclosure
If you discover a security vulnerability in MetricVault AI, we ask that you report it to us responsibly before disclosing it publicly. Please contact us at:
- Email: hello@metricvaultai.com
- Subject line: “Responsible Disclosure - [Brief Description]”
Please include as much detail as possible: the nature of the vulnerability, the steps to reproduce it, and any potential impact. We will acknowledge your report within two business days and work to resolve confirmed vulnerabilities as quickly as possible.
We ask that you not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and address it. We genuinely appreciate responsible security research and will acknowledge contributors where permitted.
6. Data Handling and Isolation
6.1 User Data Isolation
Each MetricVault AI account operates in a logically isolated environment. Your analyzed domains, reports, keyword data, and competitive intelligence outputs are visible only to you and the team members you have granted access to. We do not share one user’s submitted data or generated reports with other users.
6.2 What We Access
MetricVault AI team members may access account data only in limited circumstances:
- To investigate and resolve a support request you have raised.
- To diagnose a technical issue affecting your account
- To comply with a legal obligation or lawful government request
We maintain internal access logs for these activities.
6.3 Third-Party Data Processors
When you run an analysis, we pass the domain or URL you submit to our data providers (primarily DataForSEO) to retrieve SEO and competitive metrics. We do not pass your personal account information, email address, or other personal data to these providers beyond what is necessary for API authentication.
7. Backups and Business Continuity
We maintain automated, encrypted backups of all critical platform data on a regular schedule. Backups are stored separately from primary data stores and evaluated periodically for recoverability.
In the event of a significant incident or outage, our incident response process is designed to restore service and data integrity as quickly as possible. We will communicate status and updates through our status page at stats.uptimerobot.com and via email where an incident affects user data.
8. Security Incident Response
In the event of a security incident that affects your data, we will:
- Investigate and contain the incident as quickly as possible.
- Notify affected users promptly if the incident involves a material risk to their data.
- Notify relevant regulatory authorities as required by applicable law (e.g., within 72 hours under GDPR where applicable)
- Take corrective action to prevent recurrence.
- Provide a summary of the incident and our response to affected users upon request.
We maintain a written incident response plan that is reviewed and updated periodically.
9. Chrome Extension Security
Our Chrome extension is distributed through the official Chrome Web Store and complies with Google’s Developer Program Policies.
From a security standpoint:
- The extension requests only the permissions necessary to function. It reads the active tab URL only when you initiate an analysis.
- No passive browsing history, form data, or cookies from other sites are collected or transmitted.
- The extension communicates exclusively with our Platform servers over HTTPS.
- Extension code is not obfuscated in ways that obscure malicious behavior and is subject to the same code review processes as our main Platform.
10. What You Can Do to Stay Secure
Security is a shared responsibility. Here is what we recommend on your end:
- Use a strong, unique password for your MetricVault AI account, ideally generated by a password manager.
- Do not share your login credentials with people outside your team.
- Log out of your account when using shared or public computers.
- Keep your API keys confidential and rotate them periodically.
- Remove team member access promptly when someone leaves your organization.
- Report anything that looks suspicious at hello@metricvaultai.com
11. Compliance and Certifications
MetricVault AI is a growing platform. Our current compliance posture includes:
- GDPR compliance for EEA and UK users (see our GDPR & Data page)
- CCPA compliance for California users
- Stripe PCI-DSS Level 1 for all payment processing
We are working toward additional formal certifications as the platform scales. If your organization requires a specific compliance attestation or security questionnaire, please contact us at hello@metricvaultai.com and we will do our best to accommodate the request.
12. Contact Us
For any security-related questions, concerns, or vulnerability disclosures:
- Email: hello@metricvaultai.com
- General inquiries: hello@metricvaultai.com
- Phone: +1 (305) 563-5051
- Mailing address: MetricVault AI, Hollywood, FL 33020, USA
For non-urgent security questions or general feedback about our security practices, you can also use our standard support email. We take all security communications seriously and will respond promptly.
Security is an ongoing practice, not a one-time project. We are committed to continually improving our defenses, being transparent when things go wrong, and giving you the tools to protect your own account. If you ever have a concern, just reach out. We would rather hear from you than not.
The MetricVault AI Team · Hollywood, FL · July 2026
