Trust

Security at Citewise AI

How we protect your account, your data and your payments.

How we protect you

Encrypted in transit

All traffic is served over HTTPS with HSTS. Session cookies are HttpOnly, Secure and SameSite.

Credentials stored safely

Passwords are hashed with bcrypt. API keys are shown once and stored only as SHA-256 hashes. Password reset links are single-use and expire after one hour.

No card data on our servers

Checkout runs on Polar's hosted page. Card details never touch Citewise AI. Payment webhooks are verified with signed HMAC signatures.

Safe crawling

Free tools only fetch public internet addresses. Every request and redirect is checked to block private and internal networks.

Customer isolation

Every query is scoped to your account. Projects and results are never visible to other customers.

Official AI APIs only

We query AI providers through their official business APIs using our own keys. Your prompts are not used by us for training.

How your data is handled

  • What we store: your account details, the projects you create (brands, competitors, prompts) and the AI answers and metrics generated for you. Card details are never stored by us; Polar handles them.
  • Where it lives: in our application database on servers operated by our hosting provider. Administrative access is limited to the founder.
  • Who it's shared with: only the service providers needed to run Citewise AI, listed in our Privacy Policy. Prompts are sent to the AI providers you select; please don't include personal data in prompts.
  • Deletion: deleting a project or your account removes it from our live database immediately. You can export your results first.

Application security

  • A strict Content Security Policy, clickjacking protection and modern security headers on every response.
  • Cross-site request protection on every state-changing request, plus rate limits on sign-in, password reset, forms and free tools.
  • Changing or resetting your password signs out every other session.
  • AI answers and citations are treated as untrusted content: they're escaped before display and only web links are kept.
  • An automated end-to-end test suite covering authentication, billing, data isolation and these protections runs before every release.

Report a vulnerability

If you believe you've found a security issue, email [email protected] with the subject "Security". Please give us reasonable time to fix it before disclosure, and don't access other users' data or degrade the service while testing. We'll acknowledge your report within two business days.

Citewise AI is operated by INCAA LLC. Learn more about the company or read our Privacy Policy.