# Security and Privacy

SERPclimber is designed with security and privacy in mind, especially when handling your SEO data and publishing to your website.

## Data Access

SERPclimber only requests the permissions necessary to perform its functions.

- **Google Search Console**: We request read-only access to view your performance data and site structure.
- **CMS Integrations**: We request write access to draft and publish content, but we only modify pages that are actively part of an experiment.

## Publishing Approvals

By default, SERPclimber will never publish changes to your site without your explicit approval. You must manually review and publish drafts.

If you enable auto-publishing via [Autopilot](/documentation/projects/autopilot), you assume responsibility for the changes made to your site. We recommend starting with manual approvals until you are comfortable with the generated Drafts.

## Secrets Management

API keys and integration credentials are encrypted at rest. We use industry-standard security practices to protect your data.
