Information Security Policy
Last updated May 2026
Searchmoves Inc (doing business as Agentmoves) ("we," "us," or "our") describes here how we protect the information entrusted to us by our customers and their contacts. This policy sits alongside our Privacy Policy, which describes what information we collect and why.
Table of contents
- 1. Scope
- 2. Responsibility
- 3. Infrastructure
- 4. Encryption
- 5. Access control
- 6. Authentication
- 7. Service providers
- 8. Data retention and deletion
- 9. Backups and continuity
- 10. Monitoring
- 11. Incident response
- 12. Personnel
- 13. Customer responsibilities
- 14. What this policy does not claim
- 15. Review
- 16. How can you contact us about this policy?
1. Scope
This policy covers all systems used to deliver the AgentMoves platform, all customer data processed through it, and all personnel and contractors with access to that data.
2. Responsibility
Security is owned by the founder and CEO of Searchmoves Inc. There is no separate security team. Questions, concerns and suspected incidents should be sent to info@agentmoves.io.
3. Infrastructure
AgentMoves is delivered on third-party cloud infrastructure rather than servers we operate ourselves. Our platform is built on HighLevel's infrastructure, and we rely on their physical security, network security and platform hardening. We do not operate our own data centers and we do not have physical access to the hardware our customers' data is stored on.
Where we use additional services, we select vendors that maintain recognized security practices and publish their own security documentation.
4. Encryption
Customer data is encrypted in transit using TLS between browsers, our platform, and the services we integrate with. Data at rest is encrypted by our infrastructure providers using their standard encryption.
We do not store payment card numbers. Payments are processed by Stripe, a PCI DSS Level 1 service provider, and card data is handled entirely within Stripe's systems.
5. Access control
Access to customer data is limited to personnel who need it to deliver the service or provide support. Access is granted individually rather than through shared accounts, and is removed when someone stops working with us.
Multi-factor authentication is required on all administrative accounts that can reach customer data.
We use the access controls provided by our platform, which restrict each customer's users to their own account and data.
6. Authentication
Customer accounts are protected by individual usernames and passwords. Where a customer chooses to sign in using a third-party account such as Google or Facebook, authentication is handled by that provider.
Customers are responsible for keeping their credentials confidential, for using strong and unique passwords, and for removing access for people who leave their business.
7. Service providers
We share customer data with service providers only as necessary to deliver the platform, and under written agreements. Our principal providers are:
- HighLevel, for platform infrastructure and hosting
- Stripe, for payment processing
- OpenAI, for the AI features described in our Privacy Policy
- Google, for analytics and mapping services
We review new providers before adopting them and limit the data each one receives to what the service requires.
8. Data retention and deletion
We retain customer data for as long as a customer maintains an account with us. When an account is terminated, we deactivate or delete the data from our active systems. Some information may persist in backups for a limited period before those backups expire.
Customers may request review, correction, export or deletion of their data by contacting info@agentmoves.io. We respond in accordance with applicable data protection law.
9. Backups and continuity
Customer data is backed up by our infrastructure providers as part of their standard service. In the event of a platform outage, restoration is performed by the provider and we communicate status to affected customers.
10. Monitoring
Our platform records system activity, authentication events and errors. We review these when investigating a problem or a suspected incident.
11. Incident response
If we become aware of a security incident affecting customer data, we will:
- Contain the incident and work with the relevant provider to stop further exposure
- Determine what data was affected and whose
- Notify affected customers without undue delay, and within any timeframe required by applicable law
- Notify regulators where the law requires it
- Record what happened and what we changed to prevent a recurrence
Suspected incidents should be reported to info@agentmoves.io.
12. Personnel
Everyone with access to customer data is bound by confidentiality obligations. Access is limited to what their role requires and is removed promptly when their engagement ends.
13. Customer responsibilities
Security is shared. Customers are responsible for:
- Keeping login credentials confidential and not sharing accounts
- Removing users who no longer need access
- Ensuring they have the right to upload the contact data they bring into the platform
- Using the platform in line with our Terms of Service and with applicable marketing and privacy law
14. What this policy does not claim
We are a small business operating on established cloud infrastructure. We do not hold SOC 2, ISO 27001 or similar certifications, and we do not commission independent penetration testing. Where a customer requires a formal attestation, we can point to the certifications held by our underlying infrastructure providers.
15. Review
This policy is reviewed at least annually and whenever there is a material change to our systems or providers.
16. How can you contact us about this policy?
If you have questions or comments about this policy, you may email us at info@agentmoves.io or contact us by post at:
Searchmoves Inc4521 Saint Samons St
Carrollton, TX 75010
United States