Your workspace.
Clear boundaries.
How your account, credentials and research are handled, and how to report a problem.
Server-enforced controls protect workspace access and paid requests. No independent security certification is claimed.
- Private workspaces
- The server checks account ownership before allowing access to projects, reports and saved data.
- Encrypted credentials
- DataForSEO credentials are stored encrypted and used on the server. They are not included in browser code.
- Paid requests
- Server checks limit usage, prevent duplicate requests and require applicable cost confirmations.
- Private report responses
- Private reports use no-store responses to keep workspace data out of shared caches.
Report a vulnerability
Report privately. Include the affected version, impact and safe steps to reproduce it.
Keep the report limited.
Do not include credentials, session tokens or unrelated private data. Do not perform destructive tests or spend provider credits. Responses are best effort.