Skip to content
Local search, AI visibility, and client reporting in one evidence-backed workspace.See what's included

Security at Localense

Trust starts with boundaries you can verify.

Localense handles business, website, and authorized Google data. Our security model protects the tenant boundary first, then limits every user, integration, job, and agent to the access it needs.

Core controls

Security is part of the product architecture.

01

Tenant isolation

Every organization-scoped route resolves the caller against the organization in the path. Wrong-tenant resources return not found.

02

Scoped access

Roles, API keys, and agent clients receive explicit capabilities. Project-bound agents cannot reach another project.

03

Credential protection

Passwords are hashed. Google refresh tokens are encrypted before storage. Session and OAuth state secrets are server-side.

04

Transport and cookies

Production traffic uses HTTPS. Authentication cookies are HTTP-only, secure, and configured for the Localense domain.

05

Controlled crawling

The crawler applies redirect, body-size, timeout, concurrency, and private-network protections before processing a site.

06

Auditability

Security-sensitive changes, background jobs, webhook deliveries, and agent access retain records for review.

07

Backups and recovery

Encrypted backups follow a rolling schedule. Recovery procedures and representative restore checks are part of operations.

08

Data minimization

Google integrations request read-only or narrowly scoped access. Users choose properties and can disconnect credentials.

Responsible disclosure

Found something we should investigate?

Please send a clear description, affected URL, steps to reproduce, and impact. Do not access data that is not yours or disrupt the service.

Security contact

sohail@localense.com

We will acknowledge a good-faith report, investigate it, and coordinate remediation. This is not currently a paid bug-bounty program.

Start with your own data

See what is holding back local visibility, and what to do next.

Connect read-only Google data, run the first audit, and build an evidence-backed action plan. No charge for the first 14 days.