New Feature: AI Visibility Tracking Try It Now
iSearchFrom
Trust center

Built for teams that need clear answers.

A practical overview of how iSearchFrom handles company identity, privacy, search data, billing, and AI-agent access. This page summarizes the current public posture and links to the source documents.

Current trust brief · Published
EU 01
Operated by a registered Lithuanian company
GDPR 02
Privacy policy describes controller, rights, and lawful bases
0 03
Full payment card details stored by iSearchFrom
1 click 04
to revoke an MCP agent connection

Coverage

The questions buyers usually ask first.

Each section points back to an existing product, legal, or security surface rather than making unsupported certification claims.

Company identity

01

iSearchFrom is operated by Pakaje, UAB, with registered company details published on the site.

  • Pakaje, UAB
  • J. Basanavičiaus g. 26, Vilnius, Lithuania
  • VAT: LT100019481311
Company

Privacy and GDPR

02

The Privacy Policy explains the controller, collected data, legal bases, rights, retention, transfers, and processor categories.

  • Data controller identified
  • GDPR rights process documented
  • Privacy requests route to privacy@isearchfrom.com
Privacy

Search data handling

03

The product stores the search context needed to run, save, share, and analyze localized search workflows.

  • Queries, location, language, device, and SafeSearch context
  • Result metadata, saved searches, projects, tracked keywords, and API usage
  • Account data is retained while active and then deleted or anonymized after a limited period
FAQ

Billing and payments

04

Billing records are used for subscriptions, accounting, and tax obligations, while payment details stay with the payment processor.

  • Stripe-powered checkout and billing workflows
  • Full card details are not stored on iSearchFrom systems
  • Terms describe renewals, taxes, cancellation, and refunds
Terms

AI-agent access

05

MCP connections are approved in the browser and narrowed to the workspace, scopes, and capabilities selected during consent.

  • OAuth-based consent before access
  • Consent-time permissions plus live role checks
  • Read SQL uses a separate read-only role with row-level isolation
MCP security
06

Access and security

Public policy language covers encryption in transit, access controls, least-needed access, and incident response expectations.

  • Encryption in transit
  • Access limited to people and providers who need it
  • Security questions route to the privacy contact today
privacy@isearchfrom.com

Data lifecycle

How search and account data moves through the service.

The public privacy policy is the source of truth; this is the short operational version.

1
Collect

Only the context needed for the workflow

Searches include the query, selected market, language, device, SafeSearch settings, and result metadata needed to reproduce or analyze the check.

2
Process

Used to deliver the product

Data is used to run searches, save results, power tracking, manage subscriptions, prevent abuse, and improve the product.

3
Protect

Controls around access and providers

The policy describes encryption in transit, access controls, provider agreements, and limited access for operations, support, and incident handling.

4
Control

Requests and retention paths are documented

Users can request access, correction, erasure, restriction, objection, portability, or consent withdrawal through the privacy contact.

AI and MCP

Agent access is treated as a permissioned integration, not a blank check.

The MCP implementation uses OAuth consent, workspace binding, consent-time grants, live team-permission checks, and a separate read-only SQL path for flexible data questions.

Review the MCP security model

Published today

4/4

Available on public pages or in the current product implementation.

  • Privacy Policy and Terms of Service
  • Company identity and VAT details
  • MCP permission and read-only query guardrails
  • Privacy and support contact paths

Not published yet

0/3

Items the site should not claim until they exist as current artifacts.

  • SOC 2, ISO 27001, or similar certification report
  • A named subprocessor table with individual vendors
  • A public status page or contractual uptime SLA

Need a security review answer?

Send the question and we will answer from the current product and legal posture.

privacy@isearchfrom.com