Security at Plutoz

Plutoz stores site data, Search Console tokens and workspace secrets on your behalf. Here is how that data is protected.

Tenant isolation

Every record is scoped to a workspace and site, and enforced in the database with row-level security policies — not just in application code.

Secret handling

Integration tokens, publishing passwords and API keys are encrypted at rest and never returned to the browser. Only server-side functions can read them.

Search Console access

Plutoz requests read-only Search Console scopes, uses them solely to display your performance data inside your workspace, and lets you revoke access at any time.