SEOmise

Security & compliance

Built so that nothing happens behind your back

SEOmise connects to your website, Google Business Profile and link providers. Here is how we keep that access safe.

Two-step sign-in

Authenticator-app codes with single-use recovery codes. Platform administrators must use it. Sign-in attempts are rate-limited.

Workspace isolation

Every record belongs to one workspace and every query is scoped to it. Requests for another workspace's data answer “not found”. We test this on every release.

Encrypted credentials

Google refresh tokens, provider API keys and mail passwords are encrypted at rest and never sent to your browser. Secrets are never written to logs.

Approval gates

Paid orders and material Google Business Profile changes need explicit approval by a role allowed to give it. Orders use idempotency keys so a double click cannot buy twice.

Audit log

Approvals, spend, credential changes, external writes and security events are recorded in an append-only log, with IP addresses stored only as keyed hashes.

Safe crawling

The crawler and link checker refuse private and internal network addresses (SSRF protection), do not follow redirects blindly and respect robots.txt. See SEOmiseBot.

Browser protections

A strict Content Security Policy (no inline or third-party scripts), no framing, HTTPS with HSTS, and CSRF protection on every change.

Least privilege

Seven workspace roles map to permissions. Read-only clients cannot change anything; billing managers handle spend without touching projects.

Your data, your choice

Disconnecting Google stops sync and removes local tokens. Deleting a project or workspace removes its data, except billing records the law requires us to keep.

SEO and platform compliance

Paid placements are always shown as paid, with their placement type and known link attributes. Compliance mode prefers earned, PR, citation and rel="sponsored" or nofollow placements and flags paid dofollow links as higher risk.

For Google Business Profile, SEOmise forbids fake locations, deceptive name or category changes, invented review responses and any attempt to bypass verification. AI suggestions optimise truthful business information only.

Report a vulnerability

Found a security issue? Write to SEOmise with the steps to reproduce it. Please give us reasonable time to fix it before telling anyone else, and do not access other people's data while testing. We aim to reply within three working days.