Semrush logo
Semrush
Enterprise and security

Semrush enterprise security, SSO, audit logs and residency

A procurement-focused review of Semrush SAML SSO, roles, activity logs, security controls, compliance claims, United States hosting, DPA, subprocessors, and Enterprise terms.

Trakkr editorial teamPublished 2026-08-25
10 min read
Last updated: August 25, 2026

Quick answer

Does Semrush meet enterprise identity, security, privacy, residency, and procurement requirements?

Semrush publishes a mature procurement baseline: SAML 2.0 SSO, four account roles, corporate activity logs, TLS 1.2 or higher, penetration testing, PCI DSS Level 1, a DPA with transfer safeguards, and a named subprocessor list. Its security page says service data is stored in United States data centers. A Semrush-owned SOC 2 or ISO 27001 certification and customer-selectable regional residency are not publicly documented, so buyers should request current evidence and contract terms.

Published by Trakkr. Sources checked 2026-08-25.
Evidence: Semrush SAML SSO setup, Semrush User Management, Secure transparency in a Semrush team account, Semrush Enterprise plans and pricing, Semrush security information, Semrush Data Processing Addendum, Approved Semrush subprocessors, AI Visibility ToolkitNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence.Not publicly verified. Negotiated hosting or product-specific arrangements may exist and should be confirmed in the order form and DPA.
Single sign-on
SAML 2.0 for Guru and Business users, enabled with Semrush assistanceEvidence: Semrush SAML SSO setup
Access model
Four roles, separate logins, folder sharing, usage allocation, and admin oversightEvidence: Semrush User Management
Audit evidence
Queries, API calls, exports, invitations, login, role, and limit activity documented for team accountsEvidence: Secure transparency in a Semrush team account, Semrush Enterprise plans and pricing
Public compliance
PCI DSS Level 1; no public Semrush-owned SOC 2 or ISO 27001 claim foundEvidence: Semrush security information, Semrush Data Processing AddendumNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence.
Service data location
United States data centers according to the current Semrush security pageEvidence: Semrush security information
Transfer and processor terms
DPA includes EU SCCs, UK IDTA, audit rights, deletion or return, and breach notice without undue delayEvidence: Semrush Data Processing Addendum

Semrush enterprise procurement evidence

Semrush enterprise procurement evidence
ControlPublic evidenceOpen questionProcurement action
IdentitySAML 2.0 SSO plus email-based two-factor authenticationPassword login remains until the customer asks Semrush to disable itTest IdP flow, deprovisioning, fallback login, and emergency accessEvidence: Semrush SAML SSO setup, Semrush security information
Roles and auditFour roles, folder controls, query logs, API and export logs, and admin activityRetention, export format, and AI-toolkit event coverage are not stated in these pagesRequest a live audit-log export mapped to your control frameworkEvidence: Semrush User Management, Secure transparency in a Semrush team account, Semrush Enterprise plans and pricing
CompliancePCI DSS Level 1 and independent annual QSA audit publishedNo public Semrush-owned SOC 2 or ISO 27001 claim foundObtain the current report, certificate, scope, exceptions, and bridge letter if requiredEvidence: Semrush security information, Semrush Data Processing AddendumNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence.
Privacy and transfersDPA, EU SCCs, UK IDTA, subprocessor notice, audit, and deletion termsProduct-specific retention and returned-data charges may need clarificationAttach the DPA and approved subprocessor position to the order formEvidence: Semrush Data Processing Addendum, Approved Semrush subprocessors
ResidencyService data is stated to be stored in United States data centersNo customer-selectable AI Visibility Toolkit region is publicly documentedPut the storage, backup, support-access, and transfer locations in writingEvidence: Semrush security information, Approved Semrush subprocessors, AI Visibility Toolkit, Semrush Data Processing AddendumNot publicly verified. Negotiated hosting or product-specific arrangements may exist and should be confirmed in the order form and DPA.

Checked 25 August 2026. Public documentation is a starting point, not a substitute for the current security packet, audit evidence, order form, DPA, and negotiated Enterprise terms.

How do Semrush SSO, roles, and user access work?

Semrush documents SAML 2.0 SSO for Guru and Business users. Users must already exist before the SAML integration, Semrush helps enable it, and password login remains available until the customer asks for it to be disabled after testing.

User Management provides four roles, separate credentials, folder-level sharing, optional full sharing, usage-limit assignment, and admin oversight. Buyers should still test joiner, mover, and leaver flows because the public SAML page describes registration and authorization, not a full SCIM lifecycle.

Evidence: Semrush SAML SSO setup, Semrush User Management

What Semrush audit evidence can an administrator review?

Corporate account documentation says administrators can review prior queries, API calls, exports, invitations, role and usage-limit changes, logins, folders, and search history. Enterprise AI Optimization separately advertises team governance and audit logs.

The public pages do not state log retention, immutable export, SIEM delivery, or complete AI Visibility Toolkit event coverage. Ask Semrush to demonstrate an event from prompt change through export and show who can retrieve the record.

Evidence: Secure transparency in a Semrush team account, Semrush Enterprise plans and pricing

Is Semrush SOC 2 or ISO 27001 certified?

The current public Semrush security page claims PCI DSS Level 1 and annual independent QSA audits. It does not claim a Semrush-owned SOC 2 or ISO 27001 certification, although infrastructure providers may hold their own certificates.

Do not convert that silence into a claim that no private audit exists. If SOC 2 or ISO is a gate, request the current artifact, legal entity, system scope, audit period, exceptions, and bridge coverage directly from Semrush.

Evidence: Semrush security information, Semrush Data Processing AddendumNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence.

What should a buyer know about hosting, transfers, and legal terms?

Evidence and method

Identity and team controls are operationally documented

The SAML, User Management, and team-account guides explain eligibility, setup, roles, folder access, sharing, and logged administrator activity.

Evidence: Semrush SAML SSO setup, Semrush User Management, Secure transparency in a Semrush team account, Semrush Enterprise plans and pricing

Security practices are broader than a badge list

Semrush publishes transport encryption, backups, penetration testing, system logging, incident handling, authentication, and data-center practices on one current security page.

Evidence: Semrush security information

The legal procurement path is public

The DPA and subprocessor register provide transfer mechanisms, audit rights, notice periods, processing roles, deletion terms, and named service locations.

Evidence: Semrush Data Processing Addendum, Approved Semrush subprocessors

Certification and residency gaps are stated narrowly

The review records only what current public pages claim and treats missing SOC 2, ISO 27001, and selectable residency statements as procurement questions, not product absences.

Evidence: Semrush security information, Semrush Data Processing Addendum, Approved Semrush subprocessors, AI Visibility ToolkitNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence.Not publicly verified. Negotiated hosting or product-specific arrangements may exist and should be confirmed in the order form and DPA.

How we checked this page

We separated product access controls, internal security practices, third-party certifications, legal commitments, hosting statements, and Enterprise sales promises before drawing procurement conclusions.

  1. 1. Read the current Semrush security, SAML, User Management, team transparency, DPA, subprocessor, and Enterprise pages on 25 August 2026.
  2. 2. Distinguished Semrush-owned claims from infrastructure-provider certifications and marked undocumented evidence as uncertainty rather than unavailability.
  3. 3. Compared Trakkr only from current first-party security and pricing pages checked on the same date.
  • Limitation: We did not receive a private security packet, penetration-test report, PCI artifact, insurance certificate, audit-log export, or negotiated contract.
  • Limitation: Security controls, subprocessors, audit reports, support access, and hosting arrangements can change after the verification date.

When is Semrush or Trakkr the stronger enterprise-security fit?

Semrush has the stronger public procurement record for teams that need SAML outside a custom Enterprise deal, detailed corporate activity logs, a published DPA, subprocessor change rights, and a PCI DSS Level 1 claim. Its United States service-data statement may also simplify or block a procurement decision depending on policy.

Trakkr publishes newer encryption, row-level isolation, RBAC, MFA, and Enterprise security-review terms, but states that its own SOC 2 certification is not yet claimed. Neither vendor's current public page supplies a vendor-owned SOC 2 claim for this comparison. Choose only after reviewing private evidence and the exact contract.

Evidence: Semrush SAML SSO setup, Secure transparency in a Semrush team account, Semrush Enterprise plans and pricing, Semrush Data Processing Addendum, Approved Semrush subprocessors, Semrush security information, Security at Trakkr, Trakkr pricingNot publicly verified. The absence of a public claim does not prove that no private report, audit, or certification exists; procurement should request current evidence.

Yes. Semrush documents SAML 2.0 SSO for Guru and Business users, enabled with its team. Password login remains available until the customer explicitly asks Semrush to disable it after testing.

See how AI talks about your brand

Enter your domain to get a free AI visibility report in under 60 seconds.

14-day trialCancel anytime60 second setup