Identity and least privilege
Users, service tokens, repositories, properties and CMS connections are authorized separately and should receive only required scopes.
Security model
SEOForge separates identity, provider access, agent execution and production approval. This page describes design controls, not a claim of invulnerability or an unearned certification.
Production authority remains locked
Control layers
Users, service tokens, repositories, properties and CMS connections are authorized separately and should receive only required scopes.
Provider credentials are encrypted or hashed as appropriate, redacted from agent context and never available through API, CLI or MCP retrieval.
Every provider observation, run and artifact carries workspace and site scope; tools are allowlisted for the assigned role.
Audit events, provider health, retry state and production validation support investigation. No system is completely secure.
Prompt-injection posture
This page does not claim SOC 2, ISO 27001, PCI, HIPAA or any other certification. Completed attestations will be named only when current supporting documentation is available.
Paid deployment · human authority
Contact sales for a security conversation and available evaluation documents.