SEOmise
  1. Home
  2. Security & trust

Security & trust

Built so that nothing happens behind your back

SEOmise connects to your website, Google Business Profile and link providers. Here is how we keep that access safe — and the places to check on us.

Two-step sign-in

Authenticator-app codes with single-use recovery codes. Platform administrators must use it. Sign-in attempts are rate-limited.

Workspace isolation

Every record belongs to one workspace and every query is scoped to it. Requests for another workspace's data answer “not found”. We test this on every release.

Encrypted credentials

Google refresh tokens, provider API keys and mail passwords are encrypted at rest and never sent to your browser. Secrets are never written to logs.

Approval gates

Paid orders, site changes and material Google Business Profile changes need explicit approval by a role allowed to give it. Orders use idempotency keys so a double click cannot buy twice.

Signed publishing

Changes reach your site only as signed, scoped commands through the connector you paired. Each command is applied at most once, verified, and can be rolled back.

Audit log

Approvals, spend, credential changes, external writes and security events are recorded in an append-only log, with IP addresses stored only as keyed hashes.

Safe crawling

The crawler and link checker refuse private and internal network addresses (SSRF protection), do not follow redirects blindly and respect robots.txt.

Browser protections

A strict Content Security Policy (no inline or third-party scripts), no framing, HTTPS with HSTS, and CSRF protection on every change.

Least privilege

8 workspace roles map to permissions. Read-only clients cannot change anything; billing managers handle spend without touching projects.

Application firewall

Attack detection with automatic blocking, a sign-in log, active sessions and password and two-step policies for every account.

Your data, your choice

Disconnecting Google stops sync and removes local tokens. Deleting a project or workspace removes its data, except billing records the law requires us to keep.

Minimal cookies

Only the cookies needed to keep you signed in and to protect forms. No advertising or third-party tracking cookies.

Compliance

SEO and platform compliance

Paid placements are always shown as paid, with their placement type and known link attributes. Compliance mode prefers earned, PR, citation and rel="sponsored" or nofollow placements and flags paid dofollow links as higher risk.

For Google Business Profile, SEOmise forbids fake locations, deceptive name or category changes, invented review responses and any attempt to bypass verification. AI suggestions optimise truthful business information only.

Responsible disclosure

Report a vulnerability

Found a security issue? E-mail help@seomise.com with the steps to reproduce it. Please give us reasonable time to fix it before telling anyone else, and do not access other people's data while testing. We aim to reply within three working days.

Safe to try on your own site

Add your site and a competitor. Your first scan becomes your Day 0 baseline, and every later scan is measured against it.

Nothing is bought or published without your approval. No ranking guarantees.