Security & Compliance

Last updated: [DATE]. This page states what we handle and what we commit to. It does not claim certifications we have not earned.

What we handle

  • Page HTML / on-page copy you paste into the Studio — used only to run on-page rule checks; not published or indexed by us.
  • Email you submit for signup / lead capture (stored server-side).
  • Audit runs (inputs + rule results + ruleset version) saved to the audit log.
  • BYOK keys (Enterprise) — your OpenAI key, stored server-side only, never returned to the client. ref: OWASP ASVS

Data handling commitments

  • Inputs are used only to produce your audit; we do not train public models on them.
  • AI runs use an OpenAI-compatible endpoint (NVIDIA NIM, llama-3.1-8b) under our platform key, or your BYOK key on Enterprise.
  • Exports (JSON) contain only your own run data.
  • Payments processed by Waffo Pancake (merchant of record) — we do not store card data.

Compliance posture

  • We follow GDPR-aligned practices (lawful basis, data minimization, access on request). ref: GDPR (Art. 6, Art. 17, Art. 32)
  • We apply OWASP guidance for web app security and LLM prompt-injection hygiene. ref: OWASP
  • We do NOT claim certification (no SOC 2 / ISO 27001 badge unless earned).

⚠️ We do NOT guarantee

  • We do NOT guarantee compliance with any regulation.
  • We do NOT claim 100% security or uptime.
  • We do NOT promise the tool will "never miss" an SEO issue — rule coverage is fixed at the 10 named checks.

Subprocessors

SubprocessorPurposeRegion
Waffo PancakePayments (merchant of record)[region]
NVIDIA NIMLLM inference (platform key)[region]
VercelApp hostingGlobal edge

Replace [region] with production facts.