Security at Plutoz
Plutoz stores site data, Search Console tokens and workspace secrets on your behalf. Here is how that data is protected.
Tenant isolation
Every record is scoped to a workspace and site, and enforced in the database with row-level security policies — not just in application code.
Secret handling
Integration tokens, publishing passwords and API keys are encrypted at rest and never returned to the browser. Only server-side functions can read them.
Search Console access
Plutoz requests read-only Search Console scopes, uses them solely to display your performance data inside your workspace, and lets you revoke access at any time.