Security
Last updated: July 2026
We take the security of your account and data seriously. Some of the measures we use are described below. Security is a shared responsibility, and no system can be guaranteed completely secure.
Account security
- Passwords are stored only as salted hashes — never in plain text.
- Authentication uses signed, expiring tokens; a password reset revokes existing sessions.
- Email verification and rate limiting help protect against abuse and brute-force attempts.
Data protection
- Traffic is encrypted in transit with HTTPS/TLS.
- Publishing credentials, such as WordPress credentials, are encrypted at rest.
- Organization-level access controls help ensure each organization can access only its own data.
- Payments are processed by Stripe; we do not store full card numbers.
Infrastructure and providers
- The Service runs on reputable cloud infrastructure with least-privilege access.
- We use a limited set of vetted sub-processors (for example, payment, hosting, email, and AI model providers) to operate the Service.
Responsible disclosure
If you believe you have found a security vulnerability, please email security@oneclickgrowth.ai so we can investigate and address it. Please do not publicly disclose the issue until we have had a chance to respond.
OneClickGrowth