Security
Trust starts with boundaries you can verify.
Localense handles business data, website crawls and authorized Google data. The security model protects the tenant boundary first, then limits every user, integration, background job and agent to the narrowest access it needs to do its work.
- Read-only Google scopes
- Encrypted refresh tokens
- Project-scoped agent clients
Your workspace. Your data. Explicit access.
Core controls
Security is part of the architecture, not a setting.
These are the controls that shape how the platform is built. Each one is a property of the system rather than a policy somebody has to remember to apply.
Tenant isolation
Every organization-scoped route resolves the caller against the organization in the path. A resource that belongs to another tenant returns not found, not forbidden - the boundary does not leak existence.
Scoped access
Roles, API keys and agent clients each receive explicit capabilities. A project-bound agent client cannot read a second project, and an API key cannot exceed the role that issued it.
Credential protection
Passwords are hashed. Google refresh tokens are encrypted before storage. Session secrets and OAuth state stay server-side and are never exposed to the browser.
Transport and cookies
Production traffic is HTTPS only. Authentication cookies are HTTP-only, secure, and scoped to the Localense domain.
Controlled crawling
The crawler enforces redirect limits, body-size caps, timeouts, concurrency ceilings and private-network protections before a single page is processed, so it cannot be pointed at internal infrastructure.
Auditability
Security-sensitive changes, background jobs, webhook deliveries and agent access all retain records, so an access question can be answered from evidence rather than memory.
Backups and recovery
Encrypted backups run on a rolling schedule. Recovery procedures and representative restore checks are part of operations, not a document nobody has tested.
Data minimization
Google integrations request read-only or narrowly scoped access. You choose which properties to connect, and you can disconnect a credential at any time.
Google data
Read-only by default, and honest about what is not connected yet.
Localense's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only for user-facing features, is never sold, and is never used to train a general-purpose model.
- GSC
Search Console is connected read-only. Localense reads query, page, click, impression, CTR and position data for the properties you select, and never submits changes you did not request.
- GA4
Google Analytics 4 is connected separately and read-only. Localense cannot alter your property configuration, events or audiences.
- GBP
Business Profile API access is pending Google approval. Until it is granted, profile data is worked from CSV export or the imported profile you provide, and the interface says so rather than implying a live link.
- PLACES
Places-derived fields such as rating, review count and hours are fetched live at view time, shown with Google attribution, and never stored, snapshotted or trended - a Places API requirement enforced in the schema as well as the UI.
Not yet true
The certifications we do not have.
Security pages usually list only the wins. If you are evaluating Localense for a client with a procurement process, the gaps matter more than the badges, so here they are.
No SOC 2 or ISO 27001 certification. Localense is early, and claiming an audit we have not completed would be the exact behaviour this product exists to replace.
No paid bug bounty. Good-faith reports are acknowledged, investigated and credited, but there is no reward programme yet.
No contractual uptime SLA on self-serve plans. Availability targets are operational commitments today, not a signed guarantee.
No dedicated single-tenant hosting. Every workspace runs on the shared platform behind the tenant boundary described above.
Responsible disclosure
Found something we should investigate?
Report it directly. Please do not access data that is not yours, degrade the service for other tenants, or run automated testing that behaves like an attack while you look.
What to include
- A clear description of the issue and its impact
- The affected URL, endpoint or route
- Reproduction steps, ideally with a request or response sample
- The account or organization you tested from
A good-faith report is acknowledged, investigated and coordinated to remediation. This is not currently a paid bug-bounty program.
Security questions before you buy
Send the questionnaire before the trial, not after.
If you need answers on data residency, sub-processors, retention or deletion before you can connect a client property, ask now and get them in writing.
Read-only Google access · encrypted refresh tokens · disconnect at any time