Skip to content
Upgrade and see your AI visibility across every search engine.  Upgrade →

Security

How Onxeera protects your account and your data.

🔐

Account protection

  • Passwords are stored using WordPress's built-in password hashing — never in plain text.
  • Repeated failed login attempts from the same source are automatically rate-limited for a cooldown period.
  • Every account-changing action (billing, settings, account deletion) is protected by a per-request security token to prevent cross-site request forgery.
🔒

Data in transit

  • Login sessions use secure cookies when your connection to Onxeera is served over HTTPS.
  • Billing webhook events from our payment processor are verified using a signed HMAC signature before being trusted, so requests can't be spoofed.
🗑️

Account deletion

  • Deleting your account requires typed confirmation — it's never a single accidental click.
  • Deletion permanently removes your saved audits and competitor comparisons along with your account, rather than leaving orphaned data behind.
  • Administrator accounts can't be self-deleted through this flow, to prevent accidental lockouts.

Report a security issue

If you believe you've found a security vulnerability in Onxeera, please email us directly rather than filing a public report. We take these reports seriously and will follow up promptly.

Report a vulnerability