// Company

Security and Trust

How AEO Goal secures customer data: encryption in transit, token-based authentication, tenant-scoped data access, rate limiting, audit logging, GDPR-aligned deletion, and responsible disclosure.

Quick Answer

AEO Goal is a multi-tenant SaaS platform for AI citation tracking, AI visibility monitoring, and SEO analytics. All traffic is encrypted in transit over HTTPS. Authentication uses short-lived access tokens with rotating refresh tokens. Every data query is scoped to the owning account at the repository layer, sensitive actions are audit-logged, account deletion uses a 30-day grace period before hard deletion, and security reports go to security@aeogoal.com. AEO Goal does not claim ISO 27001 or SOC 2 certification.

Encryption in transit

All connections to AEO Goal are served over HTTPS, and browsers are instructed not to downgrade to plain HTTP. Standard hardening headers are set on every response to guard against clickjacking, content-type sniffing, and cross-site content injection.

Authentication and session security

  • Short-lived access tokens. API authentication uses short-lived access tokens, so a leaked token has only a narrow window of use.
  • Rotating refresh tokens. Refresh tokens are held in HttpOnly, Secure cookies that JavaScript cannot read and are rotated on use. Suspected token replay triggers session revocation, cutting off an attacker holding a stolen token.
  • Password security. Passwords are hashed with a modern, adaptive password-hashing algorithm, never stored or logged in plain text, and must meet strength requirements. Password reset uses single-use, expiring links and responds identically whether or not an email exists, to prevent account enumeration.
  • Abuse controls. Login and other sensitive endpoints are rate limited, and public signup is protected by layered bot controls rather than trust in a single check.

Access model and tenant isolation

AEO Goal is multi-tenant by design, and isolation is enforced structurally rather than per-endpoint. Data access goes through a shared repository layer that scopes every query to the authenticated account, so one tenant cannot read another tenant’s records. Role-based access applies inside an account, and prompts, citations, analytics, crawl results, and reports stay bound to the organization, brand, and user that own them, including in exports and background jobs. API keys, OAuth grants, and sessions are treated as credentials; customers should rotate them after any suspected exposure and avoid shared accounts.

Application and data security

Inputs are validated with typed schemas before they reach business logic, and database access uses parameterized queries, which closes the classic SQL injection path. User-supplied content is sanitized to limit cross-site scripting, and state-changing requests carry CSRF protection. Secrets are never hardcoded: configuration is loaded from the environment, and key rotation procedures are documented. Sensitive stored credentials are protected at rest.

AI-specific safeguards

Because the product itself calls AI providers, two extra controls apply. User input that flows into AI prompts is sanitized and length-bounded before it reaches a model. AI usage is metered per account with plan-level quotas and spend limits, so a compromised or misbehaving account cannot generate unbounded provider cost or traffic.

Monitoring and audit logging

Security-relevant events, including failed logins, password changes, API key generation, data exports, and permission changes, are written to an audit trail with actor, action, IP address, and timestamp. Application errors and anomalies are tracked in a monitoring pipeline with structured logs that are designed not to contain secrets.

Data handling and GDPR erasure

Customer data remains tenant-scoped for its entire lifetime. Account deletion supports the GDPR right to erasure: deletion starts a 30-day soft-delete grace period, after which hard deletion cascades through the account’s associated data, including uploaded media in object storage. Our privacy policy and data processing agreement describe the legal terms; the measurement pages describe what data the product records and why.

What this page does not claim

AEO Goal does not claim ISO 27001, SOC 2, or any other certification here, and no marketing page should be treated as compliance evidence. Enterprise buyers should request the current security documentation, subprocessor list, retention details, and incident contact workflow during procurement, and rely on signed agreements for binding commitments. Customers should never send API keys, OAuth tokens, exports, or regulated data through public marketing forms.

Responsible disclosure

If you believe you have found a security vulnerability in AEO Goal, email security@aeogoal.com. Do not open public issue-tracker tickets or disclose the issue before it is resolved. Include a description, steps to reproduce, and the potential impact; a suggested fix is welcome but not required. The team targets an initial response within 24 hours and a status update within 72 hours, with fix timelines based on severity. For anything else, use the contact page.

Frequently asked questions

Is AEO Goal ISO 27001 or SOC 2 certified?

No. AEO Goal does not claim ISO 27001, SOC 2, or any other certification on this page. Enterprise buyers should request current security documentation during procurement and rely on signed agreements, not marketing copy, for compliance commitments.

How do I report a security vulnerability in AEO Goal?

Email security@aeogoal.com with a description of the issue, steps to reproduce, and the potential impact. Do not disclose the issue publicly before it is resolved. The team targets an initial response within 24 hours.

What happens to my data when I delete my account?

Account deletion starts a 30-day soft-delete grace period, after which hard deletion cascades through the account's associated data. Customer data is tenant-scoped throughout its lifetime, including in exports and background jobs.

Run your free scan in 60 seconds

Run a free scan to see where you stand across ChatGPT, Claude, Gemini, and Perplexity: which answers cite you, which cite competitors instead, and what to fix first.

Run a free scan