Security & Data Privacy

Your CMS credentials and your brand voice, protected by design.

SEO Engine connects to WordPress and Shopify to publish for you. This page covers three things security reviewers ask first: how your keys are stored, how much access we actually request, and whether your content ever trains an AI model.

Full legal terms live on the Privacy Policy and Terms & Conditions

ENCRYPTED
WordPress••••••••••••4f2a
Shopify••••••••••••9c11
Publish access only — no admin, billing, or theme access requested
Keys encrypted at restPublish access only — nothing broaderNever used to train any AI model
How it's protected

Four boundaries between your CMS and the outside

Each one is a mechanism, not a promise — checkable in how the connection actually behaves.

API keys and CMS tokens, encrypted at rest

Your WordPress and Shopify connection credentials are encrypted in storage the moment you connect. They're never displayed again in plain text, and never appear in application logs.

Publish access only — nothing broader

Connecting a CMS grants SEO Engine permission to create and update content. It does not request admin access, billing access, user management, or theme/file access on your site.

TLS on every request

Every page and every API call, in the app and on this site, is served over HTTPS. Nothing about your account or your content travels unencrypted.

Workspace isolation, enforced at the database

Row-level access controls keep one workspace's brand kits, articles, and integrations from being reachable by another — the same isolation an agency needs between clients.

The one question enterprise buyers ask first

Your brand kit trains nothing. Not ours, not theirs.

The tone, colors, and content in your brand kit exist to generate your articles — that’s the only thing they’re used for. They’re not used to train SEO Engine’s own systems, and they’re not retained by AI model providers to train theirs.

Multi-client accounts

One agency account, walled workspaces

An agency's biggest security question isn't about us — it's about their own clients seeing each other. Each brand kit and CMS connection is scoped to its own workspace, enforced at the database.

Client A
Own brand kit · own CMS token
Client B
Own brand kit · own CMS token
Client C
Own brand kit · own CMS token
No workspace can read another workspace’s data — checked on every request

All pages and API calls are served over TLS/HTTPS, and passwords are always stored hashed — never in plain text. No method of transmission or storage is 100% secure, and we don’t claim otherwise.

Who else touches the data

Every subprocessor, named

We do not sell your data, and we share it only with the providers needed to run SEO Engine — each bound to process it only on our instructions.

Supabase
Database hosting and authentication
Razorpay
Payment processing — we never see full card details
AI model providers (e.g. Google Gemini)
Generate content from the inputs you provide, per-request
WordPress & Shopify
Only the sites you explicitly connect, only to publish
Website chat widget
On this marketing site only — not inside the app

Full detail on data collection, retention, and your rights is in the Privacy Policy.

FAQ

Questions security reviewers actually ask

No. Connections use platform-issued access tokens, not your login credentials, and those tokens are encrypted at rest the moment they're stored.

Yes — disconnecting a site from your workspace immediately stops SEO Engine from being able to publish to it. You can also revoke the connection from inside WordPress or Shopify's own app permissions.

No. The content and brand kit details sent to generate a specific article are used only to generate that article — not to train SEO Engine's systems or the underlying model providers'.

No. Row-level access controls scope every brand kit, article, and CMS connection to its own workspace — this is enforced at the database, not just in the app's UI.

Data is hosted with Supabase and retained while your account is active. Full retention and deletion terms are in the Privacy Policy.

Yes — reach out to hello@seoengine.in or through the contact page and we'll work through it directly.

Get started

Need this in writing for procurement?

Send over your security questionnaire or DPA template and we'll turn it around directly — no sales runaround.