Trust
Security at SerpKite
What we do to keep your keys, account and data safe, what we don't have yet, and how to report a vulnerability.
Controls
How we protect you
Hashed API keys
Keys look like skt_live_… and are shown once. We store only a SHA-256 hash, so a database leak does not leak usable keys. Rotate or revoke any key from the dashboard.
Hashed sessions and login tokens
Dashboard session tokens and magic-link tokens are hashed at rest too. Sessions can be listed and revoked individually.
TLS everywhere
All public endpoints are HTTPS only, terminated at Cloudflare. Traffic from Cloudflare to our servers runs through an encrypted Cloudflare Tunnel.
No inbound ports
Our servers expose no public inbound ports. All traffic arrives through the Cloudflare Tunnel, and the cluster runs default-deny network policies between services.
No query logs
We never log API keys, cookies or query text. Results are cached for a few hours under a hash of the request. Usage events keep metadata only (endpoint, status, credits, latency) and are deleted after 31 days.
Append-only credit ledger
Every credit movement is an idempotent, append-only ledger row. Refunds are compensating entries, never edits.
Spend controls
Per-key monthly credit limits and an account-wide spend cap limit the damage a leaked key can do.
Least privilege in production
Secrets live in a deploy-time secret store, not in the repository. Container images are minimal (distroless) and built in CI.
Tested backups
Database backups go to Cloudflare R2 object storage, and we test restores.
Compliance
Certifications and agreements
- SOC 2: planned, not yet started an audit. We won't claim it until we have a report.
- DPA: available; see the Data Processing Addendum.
- Subprocessors: listed on subprocessors.
- Payments: handled by Polar, our merchant of record. We never see or store card numbers.
- Collection: logged-out public results only, through proxies. See how we collect data.
Responsible disclosure
Report a vulnerability
Email [email protected] with a description, steps to reproduce and the impact you expect. We will:
- acknowledge your report within 2 business days,
- keep you updated while we investigate and fix it,
- credit you publicly if you'd like, once it's fixed.
Please don't access other users' data, degrade the service, run automated scanners at volume, or use social engineering. Test against your own account. We don't pursue good-faith research that follows these rules. We don't run a paid bug bounty yet.
Found a leaked key?
skt_live_ key in public code, email [email protected] and we'll revoke it. If it's your own key, rotate it in the dashboard right away.