Third Party Index

Snapshot 75956

Document
Security page
URL
https://heroiq.io/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
54282 bytes
SHA-256 (raw)
8ca7a044f55e894a2ebd7a12b883ac9bbd4ef24f5eea93690c2ff5895f15ec9c
SHA-256 (normalized text)
9e6e0af7023489379703449605afe8847e787871928c2d746d509751ffbf3160

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security Overview
Safe Enough For A Live Production Site.
Every plugin you add to your site is a trust decision. Here is exactly how HeroIQ keeps your website fast, stable, and secure — and your visitors' data protected.
How HeroIQ Protects Your Website
Encrypted, End to End
Every exchange between a visitor's browser and HeroIQ travels over SSL/TLS — the same encryption standard used by banks and payment processors. Nothing is sent in plain text, and the connection is verified on every request.
Locked to Your Domain
Each HeroIQ license is tied to the one website it was set up on. If the widget code is copied onto another domain, HeroIQ detects the mismatch and refuses to run. Your search widget only ever works on your site.
Time-Limited Access Tokens
The widget never sends your license key over the internet. It uses a temporary, cryptographically signed token that expires within an hour — so an intercepted token stops working almost immediately.
No Sensitive Data Exposed
Account credentials, passwords, and connected CRM keys never reach the browser or your server. They stay encrypted on HeroIQ's backend and are never included in any widget response.
Built-In Abuse Protection
Every endpoint is rate-limited, so the system can't be scraped, spammed, or overloaded by bots or bad actors — protecting your site and ours.
Passwords Never Stored in Plain Text
All account passwords are hashed with industry-standard encryption before they're saved. Nobody — including our own team — can view a customer's actual password.
Zero Risk to Your Server's Performance
The most common question we hear from developers: "Will this slow down or destabilize our site?" The answer is no — because of how HeroIQ is architected.
All AI processing happens on our cloud, never on your server. Your site never runs models or carries extra load.
Search results are pre-built and stored locally, so visitor searches are answered instantly from your own site.
If our servers are ever unreachable, your site keeps working — the widget degrades gracefully to built-in search.
Lightweight footprint: one small script, fully namespaced CSS that can't conflict with your theme, no core file changes.
Built to Enterprise Plugin Standards
HeroIQ follows the same hardening practices required of enterprise-grade website plugins.
Every request is verified with nonces (anti-forgery tokens) and capability checks — admin actions require admin permissions.
All database queries use prepared statements — no raw SQL anywhere. Inputs are sanitized and validated before processing.
Strict upload validation — file types verified by content inspection, not file names, with hard size limits.
Your Data Stays Yours
Encrypted in transit
All communication runs over HTTPS/TLS with managed, auto-renewing SSL certificates.
Complete tenant isolation
Every client's search data lives in its own isolated namespace. Another customer's data is never searched — architecturally impossible, not just filtered.
Minimal data collection
Lead capture stores only four fields: first name, last name, email, and phone. We index text content only — never images, videos, or files.
Credentials never exposed
API keys and secrets never reach the browser or appear in any response. Each license key binds to exactly one website.
Enterprise-Grade Infrastructure
SOC 2 Type II hosting
Hosted on DigitalOcean's SOC 2 Type II certified cloud with managed PostgreSQL and automated backups.
Rate limiting everywhere
Rate limiting on every endpoint protects your site and ours from abuse and automated attacks.
24/7 health monitoring
Automated checks run continuously across every service layer.
PCI DSS Level 1 payments
Payments run exclusively through Stripe. We never see or store card details, and billing webhooks are signature-verified.
SSL/TLS Encrypted SOC 2 Certified Infrastructure PCI DSS Compliant Payments Hardened Security Standards
Security reviews welcome.
Questions from your developer or IT team? We're happy to walk them through our architecture directly.
Talk to our teamSchedule a demo