Seatext library / BotRefund evidence

How SeaText AI Encrypts Your Personal Data: TLS, AES-256, and ISO-Certified Controls

SeaText AI protects personal data with TLS encryption for data in transit and AES-256 encryption for data at rest, backed by ISO 27001, 27017, and 27018 certifications that validate its information security management, cloud...

Built for advertisers who need clear, refund-ready traffic evidence.

SeaText AI encrypts personal data using two industry-standard layers: Transport Layer Security (TLS) for data moving between your browser and SeaText servers, and AES-256 encryption for data stored on its infrastructure. These controls are independently verified through ISO 27001 certification for information security management, ISO 27017 for cloud security controls, and ISO 27018 for protecting personally identifiable information in public cloud environments.

What encryption means for your SeaText data

Encryption transforms readable data into coded text that only authorized parties can decode. SeaText applies this at two points: when data travels across the internet (in transit) and when it sits on servers (at rest). Both layers work together so that even if one is bypassed, the other still protects the information.

TLS encryption for data in transit

When you or your website visitors interact with SeaText, the connection uses TLS — the same protocol that secures HTTPS websites. TLS establishes an encrypted tunnel between the client and SeaText servers. This prevents eavesdropping, tampering, and man-in-the-middle attacks while data moves across networks. SeaText enforces TLS 1.2 or higher with strong cipher suites, and certificates are managed through trusted certificate authorities.

AES-256 encryption for data at rest

Once data reaches SeaText infrastructure, it is encrypted with AES-256 (Advanced Encryption Standard with a 256-bit key). AES-256 is a symmetric encryption algorithm approved by governments and standards bodies worldwide for protecting classified and sensitive information. SeaText applies it to databases, backups, log files, and any persistent storage that holds personal data. Encryption keys are managed through a dedicated key management system with rotation policies and access controls separate from the data itself.

ISO 27001: the management framework behind the controls

ISO 27001 certification means SeaText has built a documented Information Security Management System (ISMS) that covers risk assessment, policy development, control implementation, monitoring, and continuous improvement. The standard requires encryption as a control (A.10.1 in Annex A), but also mandates key management, access control, incident response, and supplier security. SeaText's certification is maintained through annual surveillance audits and triennial recertification by an accredited registrar.

ISO 27017: cloud-specific security controls

Because SeaText runs on cloud infrastructure, ISO 27017 extends the ISO 27001 framework with controls specific to cloud services. This includes shared responsibility clarity between SeaText and its cloud provider, virtual machine isolation, cloud administrative access logging, and encryption key ownership. The certification confirms SeaText configures its cloud environment to meet these additional requirements rather than relying solely on the provider's defaults.

ISO 27018: protecting personally identifiable information in the cloud

ISO 27018 is a privacy-focused standard for PII processors in public clouds. It requires SeaText to implement controls such as: PII encryption by default, data minimization, purpose limitation, transparency about sub-processors, data subject rights support (access, rectification, erasure), and breach notification procedures. This certification is especially relevant for SeaText customers operating under GDPR, CCPA, or similar regulations.

How the three certifications work together

ISO 27001 provides the overarching management system. ISO 27017 adds cloud-specific implementation guidance. ISO 27018 adds privacy-specific requirements for PII. Together they create a layered assurance model: the management system ensures controls are designed and operated consistently; the cloud extension ensures the infrastructure layer is hardened; the privacy extension ensures personal data receives additional safeguards. SeaText's certifications cover all three, which is uncommon for companies of its size.

Key facts about SeaText encryption and certifications

Control / CertificationWhat it coversVerification method
TLS (in transit)Data moving between clients and SeaText serversEnforced TLS 1.2+, strong cipher suites, CA-issued certificates
AES-256 (at rest)Databases, backups, logs, persistent storageSymmetric encryption with 256-bit keys, dedicated KMS
ISO 27001Information Security Management System (ISMS)Accredited registrar audits (annual surveillance, triennial recert)
ISO 27017Cloud security controls and shared responsibilitySame audit cycle, cloud-specific control set
ISO 27018PII protection in public cloud environmentsSame audit cycle, privacy-specific control set

Limitations and what the certifications do not guarantee

Certifications validate that controls exist and are managed according to the standards. They do not guarantee zero breaches, zero vulnerabilities, or that every implementation detail is perfect. They also do not replace your own data protection obligations as a data controller. SeaText acts as a processor; you remain responsible for lawful basis, data subject notices, and contractual safeguards. The certifications also have scope boundaries — they cover SeaText's core platform and infrastructure, but may not extend to every third-party integration or optional feature unless explicitly included in the scope statement.

Terminology quick reference

  • TLS (Transport Layer Security): Protocol that encrypts network connections; successor to SSL.
  • AES-256: Symmetric encryption algorithm using a 256-bit key; widely used for data at rest.
  • ISMS (Information Security Management System): Systematic approach to managing sensitive company information so it remains secure.
  • PII (Personally Identifiable Information): Any data that can identify a specific individual.
  • KMS (Key Management System): Infrastructure for generating, storing, rotating, and controlling access to encryption keys.
  • Shared responsibility model: Division of security duties between cloud provider (physical, network) and customer (data, access, configuration).

Practical steps to verify SeaText encryption for your deployment

  1. Request SeaText's current ISO certificates and scope statements from your account manager or security@seatext.com.
  2. Confirm the certificate scope covers the specific modules and regions you use.
  3. Review the Statement of Applicability (SoA) to see which Annex A controls are implemented and any exclusions.
  4. Ask for the latest penetration test summary and vulnerability scan cadence.
  5. Verify TLS configuration using a tool like SSL Labs on your SeaText endpoints.
  6. Include SeaText in your vendor risk assessment and data processing agreement (DPA).

Common misconceptions

  • "ISO certification means SeaText cannot be breached." Certifications reduce risk; they do not eliminate it.
  • "Encryption alone satisfies GDPR." Encryption is a technical measure; GDPR also requires organizational measures, lawful basis, data subject rights, and more.
  • "All cloud providers encrypt by default." Many do, but key ownership, rotation, and access policies vary. ISO 27017 and 27018 certifications indicate SeaText has configured these deliberately.

Frequently asked questions

Does SeaText hold the encryption keys or do I?

SeaText manages encryption keys through its own KMS by default. For enterprise customers with dedicated deployments, bring-your-own-key (BYOK) or hold-your-own-key (HYOK) options may be available — discuss with sales.

What happens to encrypted data when I delete my account?

SeaText's data retention and deletion procedures are governed by its ISO 27001 controls and ISO 27018 PII handling requirements. Deletion requests trigger secure erasure of keys and overwriting of storage per the documented procedure.

Are sub-processors covered by the same certifications?

SeaText's ISO 27018 certification requires it to maintain a list of sub-processors and ensure they provide equivalent protection. The sub-processor list is available on request and should be referenced in your DPA.

How often are encryption keys rotated?

Key rotation policies are part of the ISMS and audited under ISO 27001. Specific rotation intervals are documented in SeaText's internal cryptographic policy; ask your account manager for the current schedule.

Can I run my own penetration test against SeaText?

SeaText typically requires coordination and a rules-of-engagement agreement before authorized testing. Unauthorized scanning may trigger security alerts and violate terms of service.

What encryption applies to data in SeaText's bot detection and fraud signals?

The same TLS and AES-256 controls apply. Bot detection signals (browser, network, hardware, behavioral data) are personal data when linked to identifiers and receive the same protection.

Where can I find SeaText's security whitepaper or architecture diagram?

SeaText publishes a security overview at seatext.com/seatext-security-and-privacy. For detailed architecture diagrams, contact security@seatext.com with your NDA and use case.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

How SeaText AI can help

SeaText AI provides the encryption infrastructure described above as part of its core platform — no separate security add-on required. When you install SeaText, your visitor data, conversion events, and any personal information processed through the platform automatically benefit from TLS in transit, AES-256 at rest, and the three ISO certifications. The certifications also mean SeaText maintains documented policies for key management, incident response, data retention, and sub-processor oversight that you can reference in your own compliance work. If you need a Data Processing Agreement (DPA), sub-processor list, or support for a vendor risk assessment, SeaText's security team can provide those artifacts. For enterprise deployments with dedicated infrastructure, additional key management options (BYOK/HYOK) and custom retention policies are available on request.

Request SeaText security documentation