Account access
Customer access uses managed authentication. Protected product routes verify the signed-in user and subscription state before returning customer content.
How Searchlight protects accounts, handles customer data, and communicates its current security posture.
The controls below describe the production product today.
Customer access uses managed authentication. Protected product routes verify the signed-in user and subscription state before returning customer content.
Customer and organization records use scoped access controls. Administrative functions require an authorized organization role.
Checkout and subscription management are handled through Stripe. Searchlight does not ask customers to send payment-card details by email or support message.
Production traffic uses HTTPS. Sensitive service credentials remain server-side and are not embedded in public product pages.
Searchlight analyzes public hiring sources and links back to evidence where available.
Account, organization, billing status, and product usage data are used to provide and operate the service.
Searchlight uses Vercel for hosting, Supabase for authentication and data services, and Stripe for payments.
For retention, user rights, and international processing details, read the Privacy policy.
Email hello@getsearchlight.io with “Security report” in the subject. Include the affected URL, what you observed, and steps to reproduce. Do not include passwords, verification codes, or payment-card details.
Searchlight does not currently claim SOC 2, ISO 27001, or independent penetration-test certification. Any future assurance will be published here with its scope.