---
title: "Security & trust - Serpwise"
description: "Serpwise sits in front of your site, so safety comes first: fail-open by design, data-minimized logging, TLS at the edge, and your origin always the source of truth."
url: "https://serpwise.ai/security/"
source: "https://serpwise.ai/security/"
---
Security & trust

# Built for production traffic.

Serpwise moves approved changes live at the edge within 60 seconds. Human approval, fail-open delivery, instant rollback, and a canonical origin keep that speed under enterprise control.

[Book a demo](/demo/) [Contact security](/contact/)

Serpwise · Security & traffic

Protection active

![Serpwise Security and Traffic workspace showing inspected requests, blocked decisions, bot traffic, and protection coverage](/product-screenshots/security-traffic.png)

Fail-open delivery

Original responses remain available

TLS at the edge

Certificates provisioned and renewed

Canonical origin

Your site stays the source of truth

Monitor what reached your site, what Serpwise acted on, and which protection needs attention next.

Live within 60 seconds

Global edge delivery after approval

Zero origin code changes

Your CMS and release flow stay untouched

Preview and rollback

Every change is controlled and reversible

Built to stay out of the way

## Safety is the default, not a setting.

Fail-open by design

If a rule misbehaves, a config is bad, or processing ever throws, the gateway returns your original page untouched. A circuit breaker and panic recovery mean an optimization can never take your site down.

Your origin is canonical

Serpwise modifies the response on the way out - it never becomes the source of truth. Turn it off and your site is exactly as it was, with relevant approved optimization data exportable where applicable.

Instant rollback

Every change is reversible. Cache invalidation is immediate, so you can roll back any rule or purge a page in seconds - no redeploy, no waiting.

TLS at the edge

Connections are served over HTTPS with certificates provisioned and renewed automatically. Traffic is encrypted in transit between your visitors and our edge.

Private & authenticated internals

The gateway isn't exposed directly. Internal services talk over a private network and authenticate every internal call with a shared key - no public control surface.

Performance-minded by default

Non-HTML assets stream straight through, HTML changes are scoped to the responses that need them, and cache behavior is reviewed during setup so optimization work does not become a performance surprise.

Data control

## Your site stays yours. Serpwise runs the optimization layer.

Serpwise is not built as a CMS replacement. Your origin remains canonical while Serpwise hosts, manages, and deploys approved optimizations so teams can move faster without tying SEO execution to one CMS, plugin, or codebase.

The customer owns the decisions

Your website, brand, SEO strategy, and approved content remain yours. Serpwise does not treat customer-approved SEO content as our property.

Execution layer, not source of truth

Changes are applied in the response path. Disable Serpwise and your origin serves the site as it did before.

CMS-independent by design

Many rule-engine changes cannot be written back consistently across WordPress, Shopify, Webflow, headless, and custom systems. Keeping execution independent is what makes the workflow portable.

Export and exit path

Relevant approved or generated optimization data can be exported where applicable, so teams can take their work with them if they stop using Serpwise.

The tradeoff is intentional: control, rollback, and portability without turning every SEO fix into a CMS release.

Data handling

## Clear about what Serpwise stores and why.

What we store

- Request metadata: path, method, response status, timing
- Bot identity (which AI/search crawler) and cache status
- Client IP and user-agent, for analytics and bot detection
- Which rules and modifications were applied
- Optimized HTML responses in Cloudflare R2 for edge delivery

What we never store

- Request bodies - handled in memory, never written to logs
- Full request headers, cookies, or session tokens
- Passwords, payment details, or form contents

How far back you can query logs is set by your plan: 30 days, 90 days, or 12 months. Need a specific retention or data-residency arrangement? Talk to us.

Honest status

## What's in place today - and what's on the roadmap.

We'd rather tell you exactly where we stand than wave a badge. Here's the real picture.

In place today

- Fail-open architecture with circuit breaker + panic recovery
- Automatic HTTPS / TLS termination at the edge
- Purpose-limited storage for request metadata and optimized HTML
- Role-based access in the dashboard (org + platform roles)
- Private, key-authenticated internal services

On the roadmap

- ~ SOC 2 - in progress; ask us for current status
- ~ Signed DPA and formal GDPR documentation
- ~ Encryption-at-rest for stored logs
- ~ Custom enterprise SLA and security review

Questions

## Security, answered.

01 What happens if Serpwise has a problem - does my site go down? + -

No. The gateway is fail-open: if a rule, config, or processing step fails, it returns your original page untouched. A circuit breaker trips to passthrough automatically, and panic recovery catches anything unexpected. Your origin is always the source of truth.

02 Do you store my visitors' data? + -

We store request metadata for analytics, and optimized HTML responses in Cloudflare R2 for edge delivery. We do not store request bodies, full request headers, cookies, session tokens, or form contents. Raw logs are kept for 12 months; how far back you can query them is set by your plan.

03 Who owns the content and SEO changes created in Serpwise? + -

The customer owns their website, brand, SEO decisions, and approved content created through Serpwise. Serpwise provides the optimization and execution layer used to manage, deploy, and test those changes; we do not treat customer-approved SEO content as our property.

04 Why doesn't Serpwise write every change directly back into the CMS? + -

Because Serpwise is designed to work across any website, CMS, framework, and custom setup. Many technical SEO changes cannot be implemented consistently across every CMS or codebase, so the independent optimization layer keeps deployment faster, safer, and less dependent on developer backlogs or plugin limitations.

05 Can we export our SEO changes if we stop using Serpwise? + -

Yes. Relevant approved or generated optimization data can be exported where applicable. The value of Serpwise is not only storing data, but giving teams a way to audit, manage, deploy, test, and scale SEO improvements without being blocked by their CMS or development workflow.

06 Is traffic encrypted? + -

Yes, in transit. Connections are served over HTTPS with certificates provisioned and renewed automatically, so traffic between your visitors and our edge is encrypted.

07 Are you SOC 2 certified? + -

SOC 2 is on our roadmap rather than complete - we'd rather be straight with you than overstate it. If you have a specific compliance or data-processing requirement, reach out and we'll walk you through where we are.

08 Can I remove Serpwise cleanly? + -

Yes. Because your origin stays canonical and changes are applied at the edge, switching Serpwise off returns traffic to your original site. Relevant approved optimization data can be exported where applicable.

Talk to us

## Have a security question? Ask us directly.

Send your security, privacy, or data-processing questions to a real person - we'll give you a straight answer, not a runaround.

[Book a demo](/demo/) [Run free audit](/audit/)