NewAI Visibility tracking is here.Try free
Security

We take this seriously - even before the certificates show up.

We’re a young company. We don’t have SOC 2 or ISO 27001 yet, and we’re not going to pretend we do. Here’s what we actually do today, what we’re working toward, who else touches your data, and how to reach our security team.

TLS 1.3 in transitEncryption at rest2FA available
What we do today

Real things, in production.

Encrypted transport

Production traffic is served over HTTPS and HTTP requests are redirected to the encrypted endpoint.

Provider encryption at rest

Production data is stored with managed infrastructure providers that support encryption at rest.

Strong password hashing + optional 2FA

Passwords are hashed with bcrypt (cost 12) - never stored in plain text. Two-factor authentication via TOTP is available to every account.

Separated service credentials

Production services use separate credentials and authenticated internal endpoints instead of public unauthenticated access.

Fail-closed production configuration

Production startup checks reject known development secrets and missing security-critical configuration.

Release security checks

Continuous-integration checks audit dependencies and block known high- or critical-severity findings from release.

On the roadmap

What we’re working toward.

Compliance work, enterprise features, and third-party audits. Items below are plans, not shipped features or certification claims.

  1. In progressNo public completion date

    SOC 2 Type II audit

    Certification requires formal scoping, an observation period, and an independent audit. We will publish verified status only after that work is complete.

  2. In progressNo public completion date

    Enterprise SSO + SCIM

    Enterprise identity-provider support and automated seat provisioning are planned, but are not included in current plan claims or contracts by default.

  3. PlannedPlanned

    ISO 27001 certification

    Formal scoping has not started. We will update this page when an accredited certification program is underway.

  4. PlannedPlanned

    EU data residency option

    Customer-selected data residency is not currently offered. Region choices will be documented here before they are sold or contracted.

  5. ScopingScoping

    Annual third-party penetration test

    A recurring independent penetration-testing program is being evaluated. We will describe the scope and evidence available after a provider is engaged.

Sub-processors

Everyone else who touches your data.

Production providers used by the platform. Optional providers only process data when the related feature is enabled. Each row links to the provider’s published privacy or processing terms.

Amazon Web Services
Application infrastructure, object storage, and email delivery
Provider-controlled regions
MongoDB Atlas
Production database hosting
Configured cloud region
Razorpay
Payment processing and subscription billing
Provider-controlled regions
DataForSEO
Keyword, ranking, backlink, and search datasets
Provider-controlled regions
Google
OAuth, Search Console connections, and optional analytics
Provider-controlled regions
Microsoft Clarity
Optional, consent-gated website analytics and session insights
Provider-controlled regions
Sentry
Application error monitoring when configured
Provider-controlled regions

Questions about a provider or current contract? Email security@seonova.io.

Found something?

Responsible disclosure.

If you found a vulnerability in SEONova, we’d like to hear about it before anyone else does. Here’s how.

What's in scope

  • seonova.io and application hosts identified as SEONova
  • Authenticated SEONova endpoints you are authorized to test
  • First-party web clients operated by Whiteunicorn Technologies

What's out of scope

  • Third-party services we don't operate (Razorpay, AWS, etc.)
  • Social engineering, physical attacks, DDoS
  • Spam, brute-force without a real auth weakness

What to expect

  • We will acknowledge and triage reports as quickly as practicable
  • Remediation timing depends on severity and complexity
  • Credit you publicly (if you want) once the fix ships

Safe harbor

  • We won't pursue legal action for good-faith research
  • We won't share your identifying details without consent
  • Stick to authorized testing - no data exfiltration, no harm

security@seonova.io

Report a suspected vulnerability with clear reproduction steps and impact.

Email security