Security & Compliance
Last updated: [DATE]. This page states what we handle and what we commit to. It does not claim certifications we have not earned.
What we handle
- Page HTML / on-page copy you paste into the Studio — used only to run on-page rule checks; not published or indexed by us.
- Email you submit for signup / lead capture (stored server-side).
- Audit runs (inputs + rule results + ruleset version) saved to the audit log.
- BYOK keys (Enterprise) — your OpenAI key, stored server-side only, never returned to the client. ref: OWASP ASVS
Data handling commitments
- Inputs are used only to produce your audit; we do not train public models on them.
- AI runs use an OpenAI-compatible endpoint (NVIDIA NIM, llama-3.1-8b) under our platform key, or your BYOK key on Enterprise.
- Exports (JSON) contain only your own run data.
- Payments processed by Waffo Pancake (merchant of record) — we do not store card data.
Compliance posture
- We follow GDPR-aligned practices (lawful basis, data minimization, access on request). ref: GDPR (Art. 6, Art. 17, Art. 32)
- We apply OWASP guidance for web app security and LLM prompt-injection hygiene. ref: OWASP
- We do NOT claim certification (no SOC 2 / ISO 27001 badge unless earned).
⚠️ We do NOT guarantee
- We do NOT guarantee compliance with any regulation.
- We do NOT claim 100% security or uptime.
- We do NOT promise the tool will "never miss" an SEO issue — rule coverage is fixed at the 10 named checks.
Subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| Waffo Pancake | Payments (merchant of record) | [region] |
| NVIDIA NIM | LLM inference (platform key) | [region] |
| Vercel | App hosting | Global edge |
Replace [region] with production facts.