Evidence before claims
The product keeps work and event records. It does not call an action completed merely because AI suggested it.
You approve sensitive changes
Public profiles, citations and website work follow explicit state and approval boundaries.
AI stays grounded
Suggestions use approved facts and available evidence, pass output checks and may still require human review.
Credentials stay server-side
OAuth tokens, service secrets and payment credentials are excluded from customer pages and exports.
Account and data control
Settings shows identity, connection and billing status; supports a secret-free account export; allows Search Console revocation; and provides an explicit, confirmation-protected deletion request. Expired and canceled customers keep access to account, retained history, billing, export, deletion and support controls.
Access boundaries
Workspace access is tenant-scoped. Revoked and anonymous users are denied protected business data. Platform support administration is separate from workspace roles, action-specific and audited. Support staff do not receive generic impersonation, entitlement, publishing, website-execution, citation-submission or deletion powers.
What we do not claim
KnownSEO does not claim SOC 2, ISO 27001, HIPAA, GDPR certification, POPIA certification, independent penetration testing or absolute security. Formal compliance posture, vendor agreements and professional legal review remain launch-governance work.
Report a concern
Authenticated customers can use private support. KnownSEO will prepare a monitored public security-reporting contact and response process for future activation. It will not publish an unmonitored address or claim a process is operational before it is ready.