Bostic.ai
← Legacy / All versions

Data Security

Security principles for a multi-tenant SEO platform that analyzes websites, stores results and runs AI-assisted workflows.

Previous publication

Security approach

Bostic.ai is designed around organization isolation, least privilege, encrypted transport, auditable access and bounded background processing.

Tenant isolation

Core customer records are scoped by organization and related project or website context. Authorization is evaluated before organization-scoped data is returned.

External URL safety

Submitted website and sitemap targets are validated at backend boundaries. Runtime fetch systems must also validate DNS resolution and redirect targets, blocking private or reserved destinations after resolution.

Job and queue safety

Dedicated SEO work lanes, active-job safeguards, stale-work recovery and tenant-aware admission help prevent duplicate or permanently blocking work.

Sensitive output

Frontend-facing job responses are designed to avoid raw stack traces, provider payloads, credentials, signed URLs and private internal paths.

Responsible disclosure

Security concerns may be sent to security@bostic.ai. Do not include active credentials or unnecessary customer data in the initial message.

Document fingerprint (SHA-256)f67a969f00afabbc25c209be06610c9c8d2fc4b95cf353b2e726d36ed6aa4402