Trust · Trust disclosure
Security depends on the systems, people, and platform boundaries involved in the request.
This overview describes the security responsibilities Semantec SEO can state publicly, the separate role of ChatGPT and other providers, the controls expected from users, and the route for reporting a concern.
Verified facts and boundaries.
These fields identify the entity, product, document, or operational boundary without turning related parties into the same entity.
Security scope.
Semantec SEO is responsible for the systems and records it controls directly, including the public website, product and support information, direct account or entitlement records, business communications, and the configuration it maintains for MIRENA.
OpenAI controls the ChatGPT platform and its account, model, platform-security, availability, conversation, memory, and data-control features. Stripe and Authflow.ai control parts of their own payment and access infrastructure.
Security principles.
- Collect and retain only the information needed for the stated purpose
- Separate product, account, privacy, payment, and ChatGPT data routes
- Restrict access to authorised roles and providers
- Use provider-supported authentication and payment controls
- Avoid receiving passwords, secret keys, full card details, and unnecessary sensitive data
- Record material incidents, changes, and remediation decisions
- Verify the target environment before deployment or publication
Account and access responsibility.
The current Founder plan is assigned to one named account and one active MIRENA instance. Subscribers must protect their credentials and comply with the separate OpenAI account rules.
Do not share, pool, rent, sell, or automate access unless a separate written arrangement and the external platform terms permit it. Report suspected unauthorised access to support@semantecseo.com.
Data minimisation is a security control.
Do not submit passwords, authentication codes, private keys, full payment-card details, regulated personal data, legal secrets, or client-confidential files unless the use is authorised and the relevant service, contract, and platform are suitable.
Remove or mask data that is not necessary for the SEO task. Use a safer route or specialist environment when the material requires stronger controls.
External providers and inherited controls.
| Provider | Public role | Security boundary |
|---|---|---|
| OpenAI / ChatGPT | Hosts the ChatGPT interface and GPT execution | OpenAI controls platform security, account rules, model access, and service availability |
| Stripe | Supports payment processing | Stripe controls its payment infrastructure and card-processing environment |
| Authflow.ai | Supports access and entitlement | Authflow.ai controls its authentication or entitlement service |
| Semantec SEO | Product, site, policies, support, and direct records | Semantec SEO controls its own configuration, access decisions, and operational handling |
Claims this page does not make.
No claim is made here of ISO 27001 certification, SOC 2 attestation, PCI DSS certification by Semantec SEO, formal penetration testing, independent security assurance, vulnerability bounty payments, guaranteed availability, or immunity from attack.
A provider's certification or security statement remains the provider's claim. It should be linked and dated before being relied on.
Report a security concern.
Email privacy@semantecseo.com with the subject 'Security report'. Include the affected URL or service, date and time, observed behaviour, potential impact, and the minimum safe steps needed to reproduce it.
Do not include exploit code beyond what is necessary, another person's data, credentials, secret keys, or full card details. The responsible-disclosure page defines the permitted reporting boundary.
Check the controlling first-party and official sources.
These routes support the current public statement. External platform and legal sources remain subject to their own updates.
Semantec SEO Privacy Policy
Current first-party provider and controller boundary.
OpenAI service terms
Official GPT and platform terms.
OpenAI usage policies
Official current rules for safe platform use.
Move to the page that owns the next question.
Each route has a separate job so company, product, trust, legal, and compliance information does not collapse into one promotional page.
Owned route
Responsible disclosure
Safe reporting scope, prohibited testing, and response process.
Open route →
Owned route
Data privacy overview
Controller, provider, and ChatGPT data boundaries.
Open route →
Owned route
Provider register
Confirmed external platforms and their public roles.
Open route →
Owned route
Acceptable Use
Account, automation, security, and prohibited-use rules.
Open route →
Owned route
Privacy Policy
Data categories, purposes, recipients, retention, and rights.
Open route →
Owned route
Contact
Product, access, security, and privacy routes.
Open route →