Skip to main content

  1. MIRENA
  2. Trust
  3. Security Overview

Trust · Trust disclosure

Security depends on the systems, people, and platform boundaries involved in the request.

This overview describes the security responsibilities Semantec SEO can state publicly, the separate role of ChatGPT and other providers, the controls expected from users, and the route for reporting a concern.

Public record

Verified facts and boundaries.

These fields identify the entity, product, document, or operational boundary without turning related parties into the same entity.

Security contactprivacy@semantecseo.com
Product supportsupport@semantecseo.com
Chat platformOpenAI controls ChatGPT security
Payment platformStripe supports payment processing
Access platformAuthflow.ai supports entitlement and access
Public certificationNone claimed on this page
01

Security scope.

Semantec SEO is responsible for the systems and records it controls directly, including the public website, product and support information, direct account or entitlement records, business communications, and the configuration it maintains for MIRENA.

OpenAI controls the ChatGPT platform and its account, model, platform-security, availability, conversation, memory, and data-control features. Stripe and Authflow.ai control parts of their own payment and access infrastructure.

02

Security principles.

  • Collect and retain only the information needed for the stated purpose
  • Separate product, account, privacy, payment, and ChatGPT data routes
  • Restrict access to authorised roles and providers
  • Use provider-supported authentication and payment controls
  • Avoid receiving passwords, secret keys, full card details, and unnecessary sensitive data
  • Record material incidents, changes, and remediation decisions
  • Verify the target environment before deployment or publication
03

Account and access responsibility.

The current Founder plan is assigned to one named account and one active MIRENA instance. Subscribers must protect their credentials and comply with the separate OpenAI account rules.

Do not share, pool, rent, sell, or automate access unless a separate written arrangement and the external platform terms permit it. Report suspected unauthorised access to support@semantecseo.com.

04

Data minimisation is a security control.

Do not submit passwords, authentication codes, private keys, full payment-card details, regulated personal data, legal secrets, or client-confidential files unless the use is authorised and the relevant service, contract, and platform are suitable.

Remove or mask data that is not necessary for the SEO task. Use a safer route or specialist environment when the material requires stronger controls.

05

External providers and inherited controls.

Current public provider boundary
Provider Public role Security boundary
OpenAI / ChatGPT Hosts the ChatGPT interface and GPT execution OpenAI controls platform security, account rules, model access, and service availability
Stripe Supports payment processing Stripe controls its payment infrastructure and card-processing environment
Authflow.ai Supports access and entitlement Authflow.ai controls its authentication or entitlement service
Semantec SEO Product, site, policies, support, and direct records Semantec SEO controls its own configuration, access decisions, and operational handling
06

Claims this page does not make.

No claim is made here of ISO 27001 certification, SOC 2 attestation, PCI DSS certification by Semantec SEO, formal penetration testing, independent security assurance, vulnerability bounty payments, guaranteed availability, or immunity from attack.

A provider's certification or security statement remains the provider's claim. It should be linked and dated before being relied on.

07

Report a security concern.

Email privacy@semantecseo.com with the subject 'Security report'. Include the affected URL or service, date and time, observed behaviour, potential impact, and the minimum safe steps needed to reproduce it.

Do not include exploit code beyond what is necessary, another person's data, credentials, secret keys, or full card details. The responsible-disclosure page defines the permitted reporting boundary.

Sources

Check the controlling first-party and official sources.

These routes support the current public statement. External platform and legal sources remain subject to their own updates.

Semantec SEO
Semantec SEO Privacy Policy

Current first-party provider and controller boundary.

Open source →

OpenAI
OpenAI service terms

Official GPT and platform terms.

Open source →

OpenAI
OpenAI usage policies

Official current rules for safe platform use.

Open source →