Two-step sign-in
Authenticator-app codes with single-use recovery codes. Platform administrators must use it. Sign-in attempts are rate-limited.
Security & compliance
SEOmise connects to your website, Google Business Profile and link providers. Here is how we keep that access safe.
Authenticator-app codes with single-use recovery codes. Platform administrators must use it. Sign-in attempts are rate-limited.
Every record belongs to one workspace and every query is scoped to it. Requests for another workspace's data answer “not found”. We test this on every release.
Google refresh tokens, provider API keys and mail passwords are encrypted at rest and never sent to your browser. Secrets are never written to logs.
Paid orders and material Google Business Profile changes need explicit approval by a role allowed to give it. Orders use idempotency keys so a double click cannot buy twice.
Approvals, spend, credential changes, external writes and security events are recorded in an append-only log, with IP addresses stored only as keyed hashes.
The crawler and link checker refuse private and internal network addresses (SSRF protection), do not follow redirects blindly and respect robots.txt. See SEOmiseBot.
A strict Content Security Policy (no inline or third-party scripts), no framing, HTTPS with HSTS, and CSRF protection on every change.
Seven workspace roles map to permissions. Read-only clients cannot change anything; billing managers handle spend without touching projects.
Disconnecting Google stops sync and removes local tokens. Deleting a project or workspace removes its data, except billing records the law requires us to keep.
Paid placements are always shown as paid, with their placement type and known link attributes. Compliance mode prefers earned, PR, citation and rel="sponsored" or nofollow placements and flags paid dofollow links as higher risk.
For Google Business Profile, SEOmise forbids fake locations, deceptive name or category changes, invented review responses and any attempt to bypass verification. AI suggestions optimise truthful business information only.
Found a security issue? Write to SEOmise with the steps to reproduce it. Please give us reasonable time to fix it before telling anyone else, and do not access other people's data while testing. We aim to reply within three working days.