Information Security Policy

Last updated May 2026

Searchmoves Inc (doing business as Agentmoves) ("we," "us," or "our") describes here how we protect the information entrusted to us by our customers and their contacts. This policy sits alongside our Privacy Policy, which describes what information we collect and why.

Table of contents

  1. 1. Scope
  2. 2. Responsibility
  3. 3. Infrastructure
  4. 4. Encryption
  5. 5. Access control
  6. 6. Authentication
  7. 7. Service providers
  8. 8. Data retention and deletion
  9. 9. Backups and continuity
  10. 10. Monitoring
  11. 11. Incident response
  12. 12. Personnel
  13. 13. Customer responsibilities
  14. 14. What this policy does not claim
  15. 15. Review
  16. 16. How can you contact us about this policy?

1. Scope

This policy covers all systems used to deliver the AgentMoves platform, all customer data processed through it, and all personnel and contractors with access to that data.

2. Responsibility

Security is owned by the founder and CEO of Searchmoves Inc. There is no separate security team. Questions, concerns and suspected incidents should be sent to info@agentmoves.io.

3. Infrastructure

AgentMoves is delivered on third-party cloud infrastructure rather than servers we operate ourselves. Our platform is built on HighLevel's infrastructure, and we rely on their physical security, network security and platform hardening. We do not operate our own data centers and we do not have physical access to the hardware our customers' data is stored on.

Where we use additional services, we select vendors that maintain recognized security practices and publish their own security documentation.

4. Encryption

Customer data is encrypted in transit using TLS between browsers, our platform, and the services we integrate with. Data at rest is encrypted by our infrastructure providers using their standard encryption.

We do not store payment card numbers. Payments are processed by Stripe, a PCI DSS Level 1 service provider, and card data is handled entirely within Stripe's systems.

5. Access control

Access to customer data is limited to personnel who need it to deliver the service or provide support. Access is granted individually rather than through shared accounts, and is removed when someone stops working with us.

Multi-factor authentication is required on all administrative accounts that can reach customer data.

We use the access controls provided by our platform, which restrict each customer's users to their own account and data.

6. Authentication

Customer accounts are protected by individual usernames and passwords. Where a customer chooses to sign in using a third-party account such as Google or Facebook, authentication is handled by that provider.

Customers are responsible for keeping their credentials confidential, for using strong and unique passwords, and for removing access for people who leave their business.

7. Service providers

We share customer data with service providers only as necessary to deliver the platform, and under written agreements. Our principal providers are:

  • HighLevel, for platform infrastructure and hosting
  • Stripe, for payment processing
  • OpenAI, for the AI features described in our Privacy Policy
  • Google, for analytics and mapping services

We review new providers before adopting them and limit the data each one receives to what the service requires.

8. Data retention and deletion

We retain customer data for as long as a customer maintains an account with us. When an account is terminated, we deactivate or delete the data from our active systems. Some information may persist in backups for a limited period before those backups expire.

Customers may request review, correction, export or deletion of their data by contacting info@agentmoves.io. We respond in accordance with applicable data protection law.

9. Backups and continuity

Customer data is backed up by our infrastructure providers as part of their standard service. In the event of a platform outage, restoration is performed by the provider and we communicate status to affected customers.

10. Monitoring

Our platform records system activity, authentication events and errors. We review these when investigating a problem or a suspected incident.

11. Incident response

If we become aware of a security incident affecting customer data, we will:

  • Contain the incident and work with the relevant provider to stop further exposure
  • Determine what data was affected and whose
  • Notify affected customers without undue delay, and within any timeframe required by applicable law
  • Notify regulators where the law requires it
  • Record what happened and what we changed to prevent a recurrence

Suspected incidents should be reported to info@agentmoves.io.

12. Personnel

Everyone with access to customer data is bound by confidentiality obligations. Access is limited to what their role requires and is removed promptly when their engagement ends.

13. Customer responsibilities

Security is shared. Customers are responsible for:

  • Keeping login credentials confidential and not sharing accounts
  • Removing users who no longer need access
  • Ensuring they have the right to upload the contact data they bring into the platform
  • Using the platform in line with our Terms of Service and with applicable marketing and privacy law

14. What this policy does not claim

We are a small business operating on established cloud infrastructure. We do not hold SOC 2, ISO 27001 or similar certifications, and we do not commission independent penetration testing. Where a customer requires a formal attestation, we can point to the certifications held by our underlying infrastructure providers.

15. Review

This policy is reviewed at least annually and whenever there is a material change to our systems or providers.

16. How can you contact us about this policy?

If you have questions or comments about this policy, you may email us at info@agentmoves.io or contact us by post at:

Searchmoves Inc
4521 Saint Samons St
Carrollton, TX 75010
United States