§Legal

    Security

    How we protect your data and keep the platform secure.

    We take a practical, honest approach to security. Below is what we actually do today, and what is still on our roadmap. We would rather understate than overclaim.

    Data Encryption

    All data transmitted between your browser and our servers is encrypted in transit using standard TLS (HTTPS). Data at rest is encrypted by our database provider (Supabase, built on PostgreSQL) using their managed encryption.

    • Encryption in transit via TLS/HTTPS on every connection
    • Encryption at rest, as provided by our managed database platform
    • Regular database backups managed by our database provider
    • Regular dependency and code security reviews

    Infrastructure Security

    Our application runs on established cloud providers: Vercel for hosting, Supabase for the EU database, and Railway for background processing. We rely on the security controls these providers operate at the platform level, which include:

    • Physical data-center security managed by our cloud providers
    • Redundant systems and provider-managed failover
    • Platform-level DDoS protection at the hosting edge
    • Provider-managed patching of the underlying infrastructure

    Access Control

    We keep access to your data tightly scoped:

    • Row-Level Security so users only ever access their own data
    • Principle of least privilege for internal access
    • Secure password policies for accounts

    Incident Response

    We monitor the application and respond to issues as they arise:

    • Application error monitoring and logging (Sentry)
    • Investigation and remediation of reported issues
    • Customer notification where an incident affects your data
    • Post-incident review and improvements

    Compliance

    Where we stand on compliance and data protection:

    • GDPR-aligned data handling
    • CCPA/CPRA support for California residents
    • Row-Level Security and least-privilege access
    • SOC 2 certification is on our roadmap (not yet certified)
    • Transparent privacy practices

    Report a Security Issue

    If you discover a security vulnerability, please report it responsibly to our security team: security@justseo.ai

    We appreciate your help in keeping JustSEO.ai secure and will acknowledge all valid reports.

    We use cookies

    We use cookies to improve your experience, analyze site traffic, and personalize content. You can customize your preferences at any time.

    Learn more: Cookie PolicyPrivacy Policy

    Customize