Trust

Security

Operational security information · Last reviewed 2 September 2026

Report a vulnerability

Please do not include passwords, API keys, payment details or other secrets in a report. Use the NOTABIS support/security contact process configured by the service owner. If no dedicated security address is published yet, this page should not be treated as a complete vulnerability disclosure policy.

Security controls

The service uses HTTPS, protected sessions, CSRF protection, rate limiting, OIDC validation, account ownership checks, signed internal crawler requests, bounded crawling and environment-managed credentials. Payment-card data is handled by the payment provider rather than the SEO application.

Crawler safety

The crawler follows robots directives, applies request limits and stops on access challenges. It is not intended to bypass controls or perform vulnerability scanning.

Known release work

Backup/restore drills, dependency auditing, monitoring, retention automation and independent security review remain release gates. See the crawler identity page and the project go-live documentation for current readiness.