Trust

Security

Last updated: June 15, 2026
Starter draft. Describes our intended security posture for early access. Confirm each control reflects your live infrastructure before publishing.

Security is built into how CiteForged works, not bolted on. The single most important property: we never need the keys to your house.

Credential-free by design

CiteForged does not ask for, store, or use logins to your website or CMS. We generate drafts and hand them off as a self-contained packet (WordPress import or copy-paste blocks) that your own team reviews and publishes. There is no path for us to modify your live site, because we never connect to it.

Workspace isolation

Each client's projects, scans, and generated artifacts live in an isolated workspace, so one customer's data is never served to another. This per-client boundary is enforced at the storage layer.

Encryption

Data is encrypted in transit (TLS) between you, our service, and the AI and search providers we query on your behalf. Persistent data is stored on managed infrastructure with encryption at rest.

Secrets handling

API keys and credentials are kept in environment configuration, never committed to source control and never exposed in client-facing output. Access to production secrets is limited to operators who need it.

Third-party processors

To deliver the Service we rely on reputable providers for AI/search (OpenAI, Perplexity, Google, xAI, Anthropic, SerpAPI), hosting, email, and payments. We share only the data needed for the requested work. See our Privacy Policy for what is processed and why.

Human in the loop

Nothing is auto-published. Compliance guardrails block risky claims before a draft reaches you, and you review and approve every Deliverable — a deliberate safeguard against both errors and abuse.

Responsible disclosure

Found a vulnerability? We want to hear from you. Email security@citeforged.com with details and steps to reproduce, and please give us a reasonable window to remediate before public disclosure. We do not pursue good-faith security research.

Contact

General security questions: hello@citeforged.com.