Launching 24 August·Pricing is already 50% off - waitlist members get an extra 10% off on launch day--d --h --m --sJoin the waitlist →
SEOGraphySEOGraphy
AboutHow It WorksPricingBlogLearnFree SEO ToolsFree AI Tools
Join Waitlist
AboutHow It WorksPricingBlogLearnFree SEO ToolsFree AI ToolsJoin Waitlist

Security at SEOGraphy

Security and privacy are part of every release. This page summarises how we protect your data, who we work with, and how to reach our security team.

Compliance

SOC 2 Type IIPlanned
On the roadmap. Audit window starts when we cross 50 enterprise customers.
GDPRIn progress
Data subject rights, consent records, and sub-processor transparency are live. Data Processing Agreement available on request; formal sign-off pending legal review.
CCPA / CPRAIn progress
Do Not Sell or Share, Global Privacy Control, and the rights to know, delete, and opt out are implemented. Final policy review pending.
PECR / ePrivacyIn progress
Cookie consent is enforced before any non-essential cookie loads, with a published cookie inventory. Final review pending.

Security controls

Encryption at rest
All data in Postgres is AES-256 encrypted at rest. BYOK keys are additionally AES-GCM encrypted at the application layer with a key never stored in the database.
Encryption in transit
TLS 1.3 enforced on every endpoint. Strict-Transport-Security with preload.
Authentication
Email + password with strong rules, OAuth (Google, GitHub, Facebook, LinkedIn, Twitter), TOTP-based MFA, and WebAuthn passkeys.
Authorisation
Postgres RLS on every table. Permission-string RBAC at the workspace level with custom roles on EXPERT.
Audit logs
Every privileged action is recorded in an account-level audit log (90-day retention, configurable, CSV export).
Backups
Continuous WAL backups with 7-day point-in-time recovery.
Vulnerability scanning
Dependabot for dependencies; CodeQL for source. Sentry for runtime monitoring.
Incident response
24-hour acknowledgement; 72-hour notification to affected customers when their data is impacted.

Subprocessors

Third parties that process customer data on our behalf. We notify customers of changes via the changelog.

ProviderPurposeDataLocation
PostgreSQL (Managed)Database, auth, storageAll app dataus-east-1
VercelApplication hostingRequest logs, build artifactsGlobal edge
StripePaymentsBilling detailsUS, EU
ResendTransactional emailEmail + nameUS
SentryError monitoringStack traces, request contextUS
AnthropicAI processingPrompts (when used)US
OpenAIAI processingPrompts (when used)US

Documents

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Cookie Policy

Report a vulnerability

If you believe you've found a security issue, please email security@example.com. We aim to acknowledge within one business day.

SEOGraphySEOGraphy

AI-powered blog writing with auto-generated images and one-click WordPress publishing.

Product

  • How It Works
  • Pricing
  • Roadmap
  • Changelog
  • Join Waitlist

Learn

  • Technical SEO
  • On-Page SEO
  • Off-Page SEO
  • Keyword Research
  • All Guides →

Free SEO Tools

  • HTTP Status Checker
  • Page Title Checker
  • Robots.txt Checker
  • Broken Link Checker
  • All Free Tools →

Free AI Tools

  • Blog Post Generator
  • AI Introduction Writer
  • AI Conclusion Writer
  • FAQ Generator
  • All Free AI Tools →

Company

  • About
  • Blog
  • Help
  • Support
  • Testimonials
PrivacyTermsCookie PolicySecurityStatus

© 2026 SEOGraphy. All rights reserved.

Made in Melbourne 🇦🇺. Built by Apptimistic