Security & data

What we can see, and what we can change

Those are the two questions worth asking before you connect a real client site to anything. The short answers: read-only access to your Search Console data, and nothing on your site changes unless you approved it, or switched autopilot on yourself. The detail is below.

Read-only access, always

Tedrix connects to Google Search Console with a read-only scope. It reads your search performance and the public content of the pages it analyses. It cannot change a setting, a property or a permission in your Search Console account.

The only route to your site

Tedrix drafts, you decide. Tedrix can only write to your site through a connection you set up yourself: our WordPress plugin, a Webflow token or a Shopify app. A change is saved so you can revert it from either side. Set up no such connection and Tedrix has no write access to your site at all.

Encrypted in transit and at rest

Every connection runs over TLS, and stored data is encrypted at rest by our hosting and database providers. Your Google and CMS access tokens carry an extra application-level encryption layer (AES-256) on top of that.

Servers and data in the EU

Our application servers run in Stockholm and the database is hosted in the EU. The honest caveat: AI drafting calls are processed by Anthropic in the USA under a data processing agreement, and only the page content being worked on is sent there.

Kept separate per client

Every site and client workspace is stored on its own, so an agency's clients never see each other's data. Getting into your workspace takes your login.

We keep little and sell nothing

We store what the product needs: your Search Console metrics, the page content we analyse, and the drafts you generate. Your data is never sold, never shared with another customer, and never used to train AI models.

Swedish company, EU rules

Tedrix is run from Sweden and built to the GDPR. We choose EU processing regions where a provider offers them, and where a provider or AI model processes data outside the EU/EEA we rely on the EU Standard Contractual Clauses.

Compliance & agreements

We operate under the GDPR. For the client data you connect and process through Tedrix, you are the controller and Tedrix is your processor. A Data Processing Agreement is available on request. Our sub-processors (hosting, payments, email delivery, Anthropic and Google APIs) are listed in the Privacy Policy.

Tedrix holds no ISO 27001 or SOC 2 certification and won't imply otherwise. If your security review needs more detail than this page gives, email info@tedrix.io.

Security & data | Tedrix