
Each local area page used to take us half a day to create and optimize.
With SEOmatic, we can create hundreds of pages in the same time, which helps our clients make the best use of their budget.
It's transformed how we deliver scalable SEO solutions.
Will Hawkins
Marketing Director, Digi-Business UK
Agents read your Search Console data, do the work, and prove what actually moved. You decide what ships.
14-Day Free Trial. $1 card check, refunded. Cancel Anytime.
Trust Center
SEOmatic's agents suggest changes to your website and, with your permission, apply them. That deserves more than promises. This page states only what the code enforces, labels what is policy, and says plainly what we have not earned yet.
Last reviewed August 26, 2026.
The exact permission each connection asks for, and what it can never do.
| Integration | Permission requested | Can we modify it? |
|---|---|---|
| Google Search Console | webmasters.readonly | No, read only. Plus the Indexing API, used only to invite Google to your own pages. |
| Google Analytics 4 | analytics.readonly | No, read only |
| Google Sheets / Drive import | spreadsheets.readonly · drive.readonly | No, read only. The Drive file picker uses the narrower drive.file scope, limited to files you pick. |
| Google Business Profile | business.manage | Only if you use GBP features |
| Google Ads (optional) | adwords | Google offers no read-only Ads scope, so this scope is full access. We only read campaign and conversion data, and only if you connect Ads. |
| Your CMS (WordPress, Shopify, Webflow…) | The token you create | Yes, that is the product. You can revoke the token in your CMS at any time. We notice and stop. |
Every CMS and integration credential you connect is encrypted with AES-256-GCM before it reaches our database, at every write path.
App servers on Hetzner (US). Database on Amazon RDS (US). Uploaded files on Amazon S3 (US).
Deleting your account schedules real deletion: after a 30 day grace period, your workspaces, connections and stored credentials are permanently deleted. Billing records are kept only as tax law requires.
Agent traffic to your site comes from our server's published IP address, so your firewall can allow it and your logs can recognize it.
The agent starts switched off. When you turn it on, you choose the mode; Assisted is recommended at setup, and you can change it anytime. Every safety rule below applies in every mode.
Level 1
DefaultEvery change waits for your click. Nothing touches your site without it.
Level 2
RecommendedSmall, reversible fixes like titles, image descriptions and links run on their own once your plan is active. Bigger work still asks first.
Level 3
Offered only after 5 clean changes with zero rollbacks. Autonomy is earned, and every change keeps its undo.
Your homepage, pricing, checkout, login, billing and legal pages are never edited automatically, in 7 languages. You can also protect any page, or a whole section with /landing/*.
Redirects, de-indexing, merges and deletions can never run unattended, in any mode. They also always require an admin.
Want image descriptions on auto but titles held back? Tick any capability and it always waits for your approval.
Unattended work stays under a daily credit cap you set. The off switch stops work in progress within one cycle.
Before any edit to an existing page, the agent saves the page as it was. Undo restores that exact version, from the task, from the activity feed, or with one workspace-wide button.
If you edited a page after the agent did, an automatic revert refuses to overwrite your work, and a manual undo warns you first.
A small automated change that measurably hurts its own page is rolled back automatically; bigger changes surface a suggested revert for your click. If a revert fails, a human on our team is alerted.
Every action lands in a permanent ledger: what changed, when, and the before and after. The receipt shows in your activity feed.
Moonshot (Kimi) is the main model, with Anthropic Claude and Mistral for specific jobs and OpenAI for images. We use each provider's business API, never their consumer products.
Moonshot is China-hosted. Workspaces marked EU-sensitive are forced onto Anthropic in code, so a routing mistake can never send their content to a non-compliant provider.
We do not train any models of our own on your data, and we use business API tiers. Provider terms vary; EU-sensitive workspaces run only on Anthropic, whose API does not train on customer content.
AI-written content must pass an independent quality review before it can go live; deterministic fixes carry a saved rollback instead. The agent refuses to invent facts, dates or links, and page content is fenced against prompt injection.
Cards only show figures computed from your own Search Console data, never a model's guess dressed up as a metric.
Every company that may handle customer data on our behalf, and why.
| Provider | Purpose | Region |
|---|---|---|
| Hetzner | Application hosting | US |
| Amazon Web Services | Database (RDS), file storage (S3) | US |
| Stripe | Payments | US / EU |
| Moonshot AI | Content writing and review (not used for EU-sensitive workspaces) | China |
| Anthropic · Mistral | Content writing and review | US / EU |
| OpenAI · Replicate | Image generation | US |
| Google APIs | Search Console, Analytics, indexing | Per Google |
| DataForSEO | Search results and keyword data | US |
| IndexMeNow | Indexing submissions of your published URLs | EU |
| Bento | Product email | US |
| PostHog | Product analytics | EU / US |
| Crisp · Featurebase | Support chat and product feedback | EU / US |
| Cloudflare | TLS for hosted custom domains | Global |
Not yet, and we would rather tell you than decorate.
Not certified. If we pursue them, this page will show real progress, not early badges.
Monitoring is internal today. A public status page and incident history are on the roadmap.
In preparation. Ask us and we will prioritize yours: contact@seomatic.ai