Semrush enterprise security, SSO, audit logs and residency
A procurement-focused review of Semrush SAML SSO, roles, activity logs, security controls, compliance claims, United States hosting, DPA, subprocessors, and Enterprise terms.
Quick answer
Does Semrush meet enterprise identity, security, privacy, residency, and procurement requirements?
Semrush publishes a mature procurement baseline: SAML 2.0 SSO, four account roles, corporate activity logs, TLS 1.2 or higher, penetration testing, PCI DSS Level 1, a DPA with transfer safeguards, and a named subprocessor list. Its security page says service data is stored in United States data centers. A Semrush-owned SOC 2 or ISO 27001 certification and customer-selectable regional residency are not publicly documented, so buyers should request current evidence and contract terms.
Key facts and evidence
- Single sign-on
- SAML 2.0 for Guru and Business users, enabled with Semrush assistanceEvidence: Semrush SAML SSO setup
- Access model
- Four roles, separate logins, folder sharing, usage allocation, and admin oversightEvidence: Semrush User Management
- Audit evidence
- Queries, API calls, exports, invitations, login, role, and limit activity documented for team accountsEvidence: Secure transparency in a Semrush team account, Semrush Enterprise plans and pricing
- Public compliance
- PCI DSS Level 1; no public Semrush-owned SOC 2 or ISO 27001 claim foundEvidence: Semrush security information, Semrush Data Processing AddendumNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence.
- Service data location
- United States data centers according to the current Semrush security pageEvidence: Semrush security information
- Transfer and processor terms
- DPA includes EU SCCs, UK IDTA, audit rights, deletion or return, and breach notice without undue delayEvidence: Semrush Data Processing Addendum
Semrush enterprise procurement evidence
| Control | Public evidence | Open question | Procurement action |
|---|---|---|---|
| Identity | SAML 2.0 SSO plus email-based two-factor authentication | Password login remains until the customer asks Semrush to disable it | Test IdP flow, deprovisioning, fallback login, and emergency accessEvidence: Semrush SAML SSO setup, Semrush security information |
| Roles and audit | Four roles, folder controls, query logs, API and export logs, and admin activity | Retention, export format, and AI-toolkit event coverage are not stated in these pages | Request a live audit-log export mapped to your control frameworkEvidence: Semrush User Management, Secure transparency in a Semrush team account, Semrush Enterprise plans and pricing |
| Compliance | PCI DSS Level 1 and independent annual QSA audit published | No public Semrush-owned SOC 2 or ISO 27001 claim found | Obtain the current report, certificate, scope, exceptions, and bridge letter if requiredEvidence: Semrush security information, Semrush Data Processing AddendumNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence. |
| Privacy and transfers | DPA, EU SCCs, UK IDTA, subprocessor notice, audit, and deletion terms | Product-specific retention and returned-data charges may need clarification | Attach the DPA and approved subprocessor position to the order formEvidence: Semrush Data Processing Addendum, Approved Semrush subprocessors |
| Residency | Service data is stated to be stored in United States data centers | No customer-selectable AI Visibility Toolkit region is publicly documented | Put the storage, backup, support-access, and transfer locations in writingEvidence: Semrush security information, Approved Semrush subprocessors, AI Visibility Toolkit, Semrush Data Processing AddendumNot publicly verified. Negotiated hosting or product-specific arrangements may exist and should be confirmed in the order form and DPA. |
Checked 25 August 2026. Public documentation is a starting point, not a substitute for the current security packet, audit evidence, order form, DPA, and negotiated Enterprise terms.
How do Semrush SSO, roles, and user access work?
Semrush documents SAML 2.0 SSO for Guru and Business users. Users must already exist before the SAML integration, Semrush helps enable it, and password login remains available until the customer asks for it to be disabled after testing.
User Management provides four roles, separate credentials, folder-level sharing, optional full sharing, usage-limit assignment, and admin oversight. Buyers should still test joiner, mover, and leaver flows because the public SAML page describes registration and authorization, not a full SCIM lifecycle.
What Semrush audit evidence can an administrator review?
Corporate account documentation says administrators can review prior queries, API calls, exports, invitations, role and usage-limit changes, logins, folders, and search history. Enterprise AI Optimization separately advertises team governance and audit logs.
The public pages do not state log retention, immutable export, SIEM delivery, or complete AI Visibility Toolkit event coverage. Ask Semrush to demonstrate an event from prompt change through export and show who can retrieve the record.
Is Semrush SOC 2 or ISO 27001 certified?
The current public Semrush security page claims PCI DSS Level 1 and annual independent QSA audits. It does not claim a Semrush-owned SOC 2 or ISO 27001 certification, although infrastructure providers may hold their own certificates.
Do not convert that silence into a claim that no private audit exists. If SOC 2 or ISO is a gate, request the current artifact, legal entity, system scope, audit period, exceptions, and bridge coverage directly from Semrush.
What should a buyer know about hosting, transfers, and legal terms?
Semrush says service data is stored in United States data centers. Its current subprocessor list includes services and locations across the United States and Ireland, while the DPA supplies EU SCCs and the UK IDTA for regulated transfers.
The DPA also covers processor instructions, security information, audit requests, subprocessor notice and objection, breach notice without undue delay, and return or deletion after termination. A customer-selectable regional residency option is not publicly documented, so residency needs an explicit contract answer.
Evidence and method
Identity and team controls are operationally documented
The SAML, User Management, and team-account guides explain eligibility, setup, roles, folder access, sharing, and logged administrator activity.
Evidence: Semrush SAML SSO setup, Semrush User Management, Secure transparency in a Semrush team account, Semrush Enterprise plans and pricingSecurity practices are broader than a badge list
Semrush publishes transport encryption, backups, penetration testing, system logging, incident handling, authentication, and data-center practices on one current security page.
Evidence: Semrush security informationThe legal procurement path is public
The DPA and subprocessor register provide transfer mechanisms, audit rights, notice periods, processing roles, deletion terms, and named service locations.
Evidence: Semrush Data Processing Addendum, Approved Semrush subprocessorsCertification and residency gaps are stated narrowly
The review records only what current public pages claim and treats missing SOC 2, ISO 27001, and selectable residency statements as procurement questions, not product absences.
Evidence: Semrush security information, Semrush Data Processing Addendum, Approved Semrush subprocessors, AI Visibility ToolkitNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence.Not publicly verified. Negotiated hosting or product-specific arrangements may exist and should be confirmed in the order form and DPA.How we checked this page
We separated product access controls, internal security practices, third-party certifications, legal commitments, hosting statements, and Enterprise sales promises before drawing procurement conclusions.
- 1. Read the current Semrush security, SAML, User Management, team transparency, DPA, subprocessor, and Enterprise pages on 25 August 2026.
- 2. Distinguished Semrush-owned claims from infrastructure-provider certifications and marked undocumented evidence as uncertainty rather than unavailability.
- 3. Compared Trakkr only from current first-party security and pricing pages checked on the same date.
- Limitation: We did not receive a private security packet, penetration-test report, PCI artifact, insurance certificate, audit-log export, or negotiated contract.
- Limitation: Security controls, subprocessors, audit reports, support access, and hosting arrangements can change after the verification date.
When is Semrush or Trakkr the stronger enterprise-security fit?
Semrush has the stronger public procurement record for teams that need SAML outside a custom Enterprise deal, detailed corporate activity logs, a published DPA, subprocessor change rights, and a PCI DSS Level 1 claim. Its United States service-data statement may also simplify or block a procurement decision depending on policy.
Trakkr publishes newer encryption, row-level isolation, RBAC, MFA, and Enterprise security-review terms, but states that its own SOC 2 certification is not yet claimed. Neither vendor's current public page supplies a vendor-owned SOC 2 claim for this comparison. Choose only after reviewing private evidence and the exact contract.
Yes. Semrush documents SAML 2.0 SSO for Guru and Business users, enabled with its team. Password login remains available until the customer explicitly asks Semrush to disable it after testing.
Yes for documented team-account activity including queries, API calls, exports, logins, invitations, and role or limit changes. Buyers should confirm retention, export, and AI-toolkit event coverage.
The current Semrush security page says service data is stored in physically secure United States data centers. A customer-selectable AI Visibility Toolkit residency region is not publicly documented.
Yes. Its DPA covers processor obligations, EU SCCs, the UK IDTA, security and audit rights, subprocessors, breach notice without undue delay, and return or deletion terms.
Sources and related reading
See how AI talks about your brand
Enter your domain to get a free AI visibility report in under 60 seconds.