NewAI Visibility tracking is here.Try free
Security

We take this seriously — even before the certificates show up.

We’re a young company. We don’t have SOC 2 or ISO 27001 yet, and we’re not going to pretend we do. Here’s what we actually do today, what we’re working toward, who else touches your data, and how to reach our security team.

TLS 1.3 in transitEncryption at rest2FA available
What we do today

Real things, in production.

TLS 1.3 in transit

Every request between your browser and our infrastructure is encrypted with modern TLS. No HTTP fallback, no legacy ciphers.

AES-256 encryption at rest

Customer data sits on encrypted volumes by default. Database backups are encrypted before they leave production.

Strong password hashing + optional 2FA

Passwords are hashed with bcrypt (cost 12) — never stored in plain text. Two-factor authentication via TOTP is available to every account.

Least-privilege internal access

Only engineers who need production access have it. Every access is logged, and access is revoked the same day employment ends.

Daily encrypted backups

Automatic backups of customer data run daily, encrypted at rest, retained for 30 days. Restoration drills run quarterly.

Vulnerability scanning on every deploy

Automated dependency + container scans run on every commit. Critical findings block release until they're patched or explicitly accepted.

On the roadmap

What we’re working toward.

Compliance work, enterprise features, and third-party audits. Target windows are real estimates — not marketing dates.

  1. In progressTargeting Q4 2026

    SOC 2 Type II audit

    Currently working with our auditors on Type I scoping. Type II observation period starts after Type I lands. We'll publish the report behind NDA once available.

  2. In progressTargeting Q3 2026

    Enterprise SSO + SCIM

    Okta, Microsoft Entra ID, Google Workspace, and generic SAML/OIDC support. SCIM 2.0 for automatic seat provisioning + deprovisioning. Rolling out to enterprise pilot first.

  3. PlannedTargeting 2027

    ISO 27001 certification

    Sits one step beyond SOC 2 for international enterprise procurement. We'll start scoping after SOC 2 Type II lands.

  4. PlannedTargeting Q4 2026

    EU data residency option

    All customer data optionally pinned to the Frankfurt region for EU enterprise plans. Default region today is US-East.

  5. ScopingLate 2026

    Annual third-party penetration test

    Engaging a qualified third party for a full-scope external + authenticated test. Summary will be available on request; remediation tracked publicly.

Sub-processors

Everyone else who touches your data.

Every third-party service that processes customer data on our behalf. Each row links to the provider’s data processing agreement.

Amazon Web Services
Application hosting, database, storage
US, EU regions
Vercel
Frontend hosting, edge network, deployments
Global edge
Cloudflare
DNS, DDoS mitigation, WAF
Global edge
Stripe
Payment processing + billing
US
Resend
Transactional email delivery
US
OpenAI
AI Visibility — ChatGPT mention tracking
US
Anthropic
AI Visibility — Claude mention tracking
US
Google Cloud
AI Visibility — Gemini mention tracking
US, EU

Material changes to this list are announced 30 days in advance. To get notified, email security@seonova.io.

Found something?

Responsible disclosure.

If you found a vulnerability in SEONova, we’d like to hear about it before anyone else does. Here’s how.

What's in scope

  • seonova.io and all subdomains (*.seonova.io)
  • Our public API and authenticated endpoints
  • First-party clients and integrations

What's out of scope

  • Third-party services we don't operate (Stripe, AWS, etc.)
  • Social engineering, physical attacks, DDoS
  • Spam, brute-force without a real auth weakness

What we commit to

  • Acknowledge your report within 1 business day
  • Investigate and respond with a timeline within 5 days
  • Credit you publicly (if you want) once the fix ships

Safe harbor

  • We won't pursue legal action for good-faith research
  • We won't share your identifying details without consent
  • Stick to authorized testing — no data exfiltration, no harm

security@seonova.io

The fastest way to reach our security team. Encrypted communication via PGP available on request.

Email security

status.seonova.io

Real-time system status, ongoing incidents, and scheduled maintenance windows.

Open status page