Security & Compliance

Built for Teams That
Have to Answer for This.

Every account gets an audit trail, session protection, and rate limiting by default. Enterprise and Agency accounts add SSO/SAML and SOC 2 controls for teams whose security review is part of the buying process.

What’s In Place

🛡

Audit Log

Records every security-relevant event — settings changes, API key changes, team permission changes, failed logins, rate limit violations — with old and new values.

Session Security

Enforces inactivity-based session expiry for subscriber accounts, stricter than the WordPress default, with timeout events logged to the audit trail.

🛑

Rate Limiting

Per-user request throttling on every sensitive endpoint, preventing abuse and runaway consumption before it becomes a problem.

🔑

SSO / SAML

Single sign-on for Enterprise accounts, so access follows your existing identity provider instead of a separate password.

SOC 2 Controls

Documented controls in place for Enterprise accounts going through vendor security review.

Talk to Us About Your Security Review.

Enterprise and Agency plans include SSO/SAML and SOC 2 documentation.

Book a Demo