Preview build. Not for public indexing. Legal documents are drafts with unfilled placeholders, and 9 marketed capabilities are still pending SaaS phases. See PRODUCT_AVAILABILITY.md for the launch gates.

Security

Security designed around least access, tenant isolation and non-readable secrets

WindspeedSEO handles read-only access to your Google data and, on Managed Automation, write access to your website. This page describes how that access is limited, separated, stored and revoked.

Contact usSee integrations

Principles

Four principles shape every access decision in the product, and each one is visible in how the integrations actually behave.

  • Least access. Each integration requests the narrowest permission that lets it work. Where reading is sufficient, only reading is requested.
  • Separation by purpose. Machine work and human work use different credentials. Provisioning and publishing use different credentials again.
  • Explicit tenant context. Every request carries organization context, so one customer’s data and connections are never reachable from another’s session.
  • Secrets are not readable. Stored credentials are encrypted at rest and never displayed again after saving — only rotated or revoked.

Google access

Read-only scopes

Search Console and Analytics 4 connections request read access only. WindspeedSEO does not submit sitemaps, request indexing, change property settings, or create or modify anything in your Analytics configuration.

Revocable by you, at any time

Connections can be removed from your WindspeedSEO account or revoked directly from your Google account. Revocation stops further collection immediately.

WordPress access — Managed Automation only

No customer password

You are never asked to provide your normal WordPress password. Machine credentials are issued for the purpose instead.

Separate machine credentials

One credential for provisioning, another for publishing. Either can be rotated or revoked independently of the other.

Restricted developer role

A custom SEO developer role, not the built-in Administrator role. User management is denied, as are the plugin and theme code capabilities that would allow the restriction to be bypassed.

Individual accounts

Every human developer has an individually mapped WordPress user. No shared accounts, so every change is attributable.

Short-lived signed sign-on

Single-use and time-limited, with asymmetric signature verification preferred. No standing session remains after the work.

Separate publishing identity

The public byline on published content is distinct from the machine accounts, and its biography uses verified facts only.

See the WordPress connection in detail

Platform credential handling

Administrator-managed integration credentials are encrypted at rest and are not retrievable in plaintext after they are saved. The interface supports versioning, rotation, testing and revocation rather than display. Bootstrap database and encryption secrets are deployment secrets and are never held in application configuration visible to users.

Secrets do not appear in source control, logs, prompts, screenshots or support material, and customer data is not stored in GitHub.

Data handling

What is collected, why, where it is stored, how long it is retained and how it is deleted is described in the privacy policy. The current list of external providers that process data on our behalf is published on the subprocessors page.

If payment is unresolved, SEO execution pauses: data refreshes, external provider work and publishing stop. Entitlement is rechecked at the moment work would execute, so nothing keeps running in the background.

Reporting a security issue

If you believe you have found a vulnerability, contact us with the details at [REQUIRED: security contact address]. Please do not test against other customers’ accounts or data.

To be published before launch

A dedicated security contact address, and any published disclosure process or response commitment, will be added here.

Pre-launch note

Legal entity details, business address, governing law and published contact addresses are being finalized before public launch and are marked as required throughout this website.

See the WindspeedSEO overview, or read the plans to understand which access applies to you.

Questions about security or data handling?

Send us the specifics and we will answer them directly rather than pointing you at a brochure.

Contact usRead the privacy policy