We take this seriously - even before the certificates show up.
We’re a young company. We don’t have SOC 2 or ISO 27001 yet, and we’re not going to pretend we do. Here’s what we actually do today, what we’re working toward, who else touches your data, and how to reach our security team.
Real things, in production.
Encrypted transport
Production traffic is served over HTTPS and HTTP requests are redirected to the encrypted endpoint.
Provider encryption at rest
Production data is stored with managed infrastructure providers that support encryption at rest.
Strong password hashing + optional 2FA
Passwords are hashed with bcrypt (cost 12) - never stored in plain text. Two-factor authentication via TOTP is available to every account.
Separated service credentials
Production services use separate credentials and authenticated internal endpoints instead of public unauthenticated access.
Fail-closed production configuration
Production startup checks reject known development secrets and missing security-critical configuration.
Release security checks
Continuous-integration checks audit dependencies and block known high- or critical-severity findings from release.
What we’re working toward.
Compliance work, enterprise features, and third-party audits. Items below are plans, not shipped features or certification claims.
- In progressNo public completion date
SOC 2 Type II audit
Certification requires formal scoping, an observation period, and an independent audit. We will publish verified status only after that work is complete.
- In progressNo public completion date
Enterprise SSO + SCIM
Enterprise identity-provider support and automated seat provisioning are planned, but are not included in current plan claims or contracts by default.
- PlannedPlanned
ISO 27001 certification
Formal scoping has not started. We will update this page when an accredited certification program is underway.
- PlannedPlanned
EU data residency option
Customer-selected data residency is not currently offered. Region choices will be documented here before they are sold or contracted.
- ScopingScoping
Annual third-party penetration test
A recurring independent penetration-testing program is being evaluated. We will describe the scope and evidence available after a provider is engaged.
Everyone else who touches your data.
Production providers used by the platform. Optional providers only process data when the related feature is enabled. Each row links to the provider’s published privacy or processing terms.
Questions about a provider or current contract? Email security@seonova.io.
Responsible disclosure.
If you found a vulnerability in SEONova, we’d like to hear about it before anyone else does. Here’s how.
What's in scope
- seonova.io and application hosts identified as SEONova
- Authenticated SEONova endpoints you are authorized to test
- First-party web clients operated by Whiteunicorn Technologies
What's out of scope
- Third-party services we don't operate (Razorpay, AWS, etc.)
- Social engineering, physical attacks, DDoS
- Spam, brute-force without a real auth weakness
What to expect
- We will acknowledge and triage reports as quickly as practicable
- Remediation timing depends on severity and complexity
- Credit you publicly (if you want) once the fix ships
Safe harbor
- We won't pursue legal action for good-faith research
- We won't share your identifying details without consent
- Stick to authorized testing - no data exfiltration, no harm
security@seonova.io
Report a suspected vulnerability with clear reproduction steps and impact.
Email security