Security claims you can check
See the controls implemented in the product, the data the service needs, and the certifications AIGrow does not currently hold. A written project scope covers anything beyond the public product.
No SOC 2 or ISO 27001 certification is claimed. Privacy requests go to [email protected].
- Production transport
- HTTPS
- Account password stored
- none
- Card collection
- Stripe hosted
- SOC 2 Type II
- not certified
- Published penetration report
- none
Custom requirements belong in a written scope before data or credentials are shared.
What the current product does
These statements describe implemented product behavior or a requirement for scoping custom access.
HTTPS on public services
The website, account flow and API are served over HTTPS in production. The API also sends content security, frame, referrer and content-type headers on its JSON responses.
Passwordless account access
AIGrow uses email sign-in links and Google OAuth. The product does not ask you to create or store an AIGrow password.
Hosted payment collection
Paid checkout opens a Stripe-hosted page. AIGrow records the customer, subscription and purchase state needed to provide the service, without collecting full card details in its own form.
Encrypted connector credentials
Google Search Console credentials submitted through Blog Engine are encrypted before database storage. The service refuses that feature when its encryption key is not configured.
Scoped project access
A custom project scope should name each system, permission and data flow before access is granted. If a connector cannot be limited safely, that constraint belongs in the written scope.
No borrowed certification badge
A cloud provider certificate does not certify AIGrow. This page states the current AIGrow status directly so a buyer can decide whether it meets procurement requirements.
Current status, without borrowed badges
Provider certifications and a future roadmap do not certify AIGrow. Procurement decisions should use the status shown here.
What people ask
Storage, providers, deployment, testing and incident reporting.