Your CMS credentials and your brand voice, protected by design.
SEO Engine connects to WordPress and Shopify to publish for you. This page covers three things security reviewers ask first: how your keys are stored, how much access we actually request, and whether your content ever trains an AI model.
Full legal terms live on the Privacy Policy and Terms & Conditions
Four boundaries between your CMS and the outside
Each one is a mechanism, not a promise — checkable in how the connection actually behaves.
API keys and CMS tokens, encrypted at rest
Your WordPress and Shopify connection credentials are encrypted in storage the moment you connect. They're never displayed again in plain text, and never appear in application logs.
Publish access only — nothing broader
Connecting a CMS grants SEO Engine permission to create and update content. It does not request admin access, billing access, user management, or theme/file access on your site.
TLS on every request
Every page and every API call, in the app and on this site, is served over HTTPS. Nothing about your account or your content travels unencrypted.
Workspace isolation, enforced at the database
Row-level access controls keep one workspace's brand kits, articles, and integrations from being reachable by another — the same isolation an agency needs between clients.
Your brand kit trains nothing. Not ours, not theirs.
The tone, colors, and content in your brand kit exist to generate your articles — that’s the only thing they’re used for. They’re not used to train SEO Engine’s own systems, and they’re not retained by AI model providers to train theirs.
One agency account, walled workspaces
An agency's biggest security question isn't about us — it's about their own clients seeing each other. Each brand kit and CMS connection is scoped to its own workspace, enforced at the database.
All pages and API calls are served over TLS/HTTPS, and passwords are always stored hashed — never in plain text. No method of transmission or storage is 100% secure, and we don’t claim otherwise.
Every subprocessor, named
We do not sell your data, and we share it only with the providers needed to run SEO Engine — each bound to process it only on our instructions.
Full detail on data collection, retention, and your rights is in the Privacy Policy.
Questions security reviewers actually ask
No. Connections use platform-issued access tokens, not your login credentials, and those tokens are encrypted at rest the moment they're stored.
Yes — disconnecting a site from your workspace immediately stops SEO Engine from being able to publish to it. You can also revoke the connection from inside WordPress or Shopify's own app permissions.
No. The content and brand kit details sent to generate a specific article are used only to generate that article — not to train SEO Engine's systems or the underlying model providers'.
No. Row-level access controls scope every brand kit, article, and CMS connection to its own workspace — this is enforced at the database, not just in the app's UI.
Data is hosted with Supabase and retained while your account is active. Full retention and deletion terms are in the Privacy Policy.
Yes — reach out to hello@seoengine.in or through the contact page and we'll work through it directly.
Need this in writing for procurement?
Send over your security questionnaire or DPA template and we'll turn it around directly — no sales runaround.