## **What This Means and Why It Matters**

If you notice projects in your Search Atlas account that you or your team did not create, this is a serious security concern. Unauthorized projects can indicate that your account credentials have been compromised, that a former team member still has access, or that account sessions are being shared unintentionally. Act quickly — the steps below will help you contain the issue and prepare the information our team needs to investigate.

## **Step 1 — Audit Your Team Members**

Start by reviewing who currently has access to your account. Look through your account's user or team management settings for anyone you do not recognise, former employees, or accounts with unexpected permission levels. Remove access for any user who should not have it, and re-invite legitimate users with fresh invitations if needed.

Even one unfamiliar user account can be the entry point for unauthorized activity. If in doubt, remove access and re-invite legitimate users.

## **Step 2 — Change Your Password Immediately**

If you suspect your credentials have been exposed, reset your password right away through your account settings. Set a new, strong password that is unique to Search Atlas — do not reuse passwords from other services. If your organisation uses shared login credentials, ask all legitimate team members to update their passwords and switch to individual accounts where possible.

## **Step 3 — Document the Unauthorized Projects**

Before removing anything, collect evidence so our team can investigate effectively.

- Take screenshots of any projects you did not create, including project names, creation dates, and any associated URLs or keywords.
- Note the approximate date when you first noticed the activity.
- Record any other unusual behaviour, such as unexpected changes to existing projects, billing anomalies, or unfamiliar API usage.

Do **not** delete the unauthorized projects yet — preserving them allows our security team to trace the source of the activity.

## **Step 4 — Revoke Unrecognised API Keys and Integrations**

Unauthorized access can sometimes originate from an exposed API key or a connected third-party tool. Review any active API keys linked to your account and revoke any that you do not recognise or no longer use. Check connected integrations and remove any unauthorised connections. If your credentials were stored in a shared document, spreadsheet, or code repository, remove them immediately.

## **Step 5 — Escalate to Our Security Team**

Because investigating unauthorized account activity requires backend access to audit logs and session data, our team will need to take action on your behalf. To help us investigate as quickly as possible, please have the following ready when you contact us:

- Your account email address and the name of the affected workspace or organisation.
- Screenshots and notes collected in Step 3.
- The names of any users removed in Step 1 and any API keys revoked in Step 4.
- The approximate date you first noticed the unauthorized activity.

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type **human teammate** to be connected with a member of our team.