SEOVENTRA
Security

Built with security
as a foundation.

SEOVentra handles sensitive data β€” your domains, GSC tokens, and indexing pipelines. Here is how we protect it and what you can expect from us.

Security contact
Responsible disclosure
hello@seoventra.com
Response time
We aim to respond within 48 hours
Infrastructure
Cloudflare Workers, D1, R2
Our practices
πŸ”
Data encryption

All data in transit is protected by TLS 1.3. Data at rest in Cloudflare D1 is encrypted using AES-256. Backups are encrypted before storage.

πŸ”‘
Passwordless authentication

SEOVentra uses magic link authentication β€” we never store passwords. Each login link is single-use, time-limited, and cryptographically signed.

🏒
Role-based access control

Organisations have admin, member, and viewer roles. API keys are scoped per-project with configurable permission levels.

🌍
Edge infrastructure

Built entirely on Cloudflare's global edge network. No single-region data concentration. Workers and D1 operate under Cloudflare's enterprise security posture.

πŸ”
Minimal data collection

We collect only what's needed to operate the platform. We do not sell data, run ads, or share your site data with third parties. Full details in our Privacy Policy.

πŸ›‘
API key security

API keys are displayed once at creation and never stored in plaintext. Keys can be rotated or revoked instantly from your dashboard settings.

Third-party integrations
Google Search Console

OAuth service account access. Tokens stored encrypted. We request only the minimum necessary scopes (URL inspection and indexing submission). Tokens can be revoked from your Google account at any time.

Anthropic Claude API

Used for AI visibility scoring. Your page content is sent to Claude for analysis. We do not retain page content beyond the scoring request. You can supply your own API key on Pro and Business plans.

Resend (email)

Used to deliver magic link login emails and alert notifications. Only your email address is shared. No marketing without explicit consent.

Razorpay (billing)

Handles payment processing for paid plans. We never see or store your full card details. Razorpay is PCI DSS compliant. Subscription and billing data is stored with Razorpay, not SEOVentra.

Responsible disclosure

Found a
vulnerability?

We appreciate responsible security researchers. If you discover a vulnerability in SEOVentra, please report it to us privately before public disclosure.

Report a vulnerability
Guidelines
01Email your finding to hello@seoventra.com with a clear description of the issue
02Include steps to reproduce and any relevant evidence (screenshots, logs, proof of concept)
03Do not access, modify, or exfiltrate data that is not yours
04Do not perform denial-of-service testing or social engineering
05Allow us reasonable time to investigate and respond before public disclosure
Privacy PolicyTerms of ServiceContact Us