We take this seriously — even before the certificates show up.
We’re a young company. We don’t have SOC 2 or ISO 27001 yet, and we’re not going to pretend we do. Here’s what we actually do today, what we’re working toward, who else touches your data, and how to reach our security team.
Real things, in production.
TLS 1.3 in transit
Every request between your browser and our infrastructure is encrypted with modern TLS. No HTTP fallback, no legacy ciphers.
AES-256 encryption at rest
Customer data sits on encrypted volumes by default. Database backups are encrypted before they leave production.
Strong password hashing + optional 2FA
Passwords are hashed with bcrypt (cost 12) — never stored in plain text. Two-factor authentication via TOTP is available to every account.
Least-privilege internal access
Only engineers who need production access have it. Every access is logged, and access is revoked the same day employment ends.
Daily encrypted backups
Automatic backups of customer data run daily, encrypted at rest, retained for 30 days. Restoration drills run quarterly.
Vulnerability scanning on every deploy
Automated dependency + container scans run on every commit. Critical findings block release until they're patched or explicitly accepted.
What we’re working toward.
Compliance work, enterprise features, and third-party audits. Target windows are real estimates — not marketing dates.
- In progressTargeting Q4 2026
SOC 2 Type II audit
Currently working with our auditors on Type I scoping. Type II observation period starts after Type I lands. We'll publish the report behind NDA once available.
- In progressTargeting Q3 2026
Enterprise SSO + SCIM
Okta, Microsoft Entra ID, Google Workspace, and generic SAML/OIDC support. SCIM 2.0 for automatic seat provisioning + deprovisioning. Rolling out to enterprise pilot first.
- PlannedTargeting 2027
ISO 27001 certification
Sits one step beyond SOC 2 for international enterprise procurement. We'll start scoping after SOC 2 Type II lands.
- PlannedTargeting Q4 2026
EU data residency option
All customer data optionally pinned to the Frankfurt region for EU enterprise plans. Default region today is US-East.
- ScopingLate 2026
Annual third-party penetration test
Engaging a qualified third party for a full-scope external + authenticated test. Summary will be available on request; remediation tracked publicly.
Everyone else who touches your data.
Every third-party service that processes customer data on our behalf. Each row links to the provider’s data processing agreement.
Material changes to this list are announced 30 days in advance. To get notified, email security@seonova.io.
Responsible disclosure.
If you found a vulnerability in SEONova, we’d like to hear about it before anyone else does. Here’s how.
What's in scope
- seonova.io and all subdomains (*.seonova.io)
- Our public API and authenticated endpoints
- First-party clients and integrations
What's out of scope
- Third-party services we don't operate (Stripe, AWS, etc.)
- Social engineering, physical attacks, DDoS
- Spam, brute-force without a real auth weakness
What we commit to
- Acknowledge your report within 1 business day
- Investigate and respond with a timeline within 5 days
- Credit you publicly (if you want) once the fix ships
Safe harbor
- We won't pursue legal action for good-faith research
- We won't share your identifying details without consent
- Stick to authorized testing — no data exfiltration, no harm
security@seonova.io
The fastest way to reach our security team. Encrypted communication via PGP available on request.
Email securitystatus.seonova.io
Real-time system status, ongoing incidents, and scheduled maintenance windows.
Open status page