Security & Trust

You're always in control of changes to your website.

webioom separates finding problems from changing your site. Supported changes follow a controlled workflow designed to confirm the target, require your approval, and give you visibility into what happened.

Scanning is separate from fixing

Scanning a website does not itself authorize webioom to edit it — the two are distinct.

You approve supported changes

Current direct-fix workflows require your explicit approval before anything is applied.

Credentials stay server-side

Connected credentials are handled on webioom's servers, not intentionally rendered into the browser.

Changes are narrowly scoped

A supported fix targets one specific, confirmed field or resource — never a broad, uncontrolled edit.

Fresh checks before Apply

webioom re-checks the relevant state right before a supported write, so a stale preview is never blindly applied.

Verified after Apply

Supported workflows verify the result of a change, where verification is available.

History gives visibility

Every successful supported write is recorded, so you can see exactly what changed.

Undo where safe

Supported changes can be undone when webioom can safely confirm the current target and state.

Refuses rather than guesses

If webioom cannot safely confirm the target or current state, it stops instead of attempting an uncertain write.

Find
Prepare
You Review
Apply
Verify
Record

The important step is yours: nothing in the current supported direct-fix workflow is applied until you approve it.

How connected credentials are handled

When you connect a supported integration like WordPress, the credential you provide is:

  • Handled server-side — never processed or stored in your browser session
  • Stored encrypted at rest
  • Never displayed back as raw credentials anywhere in the product
  • Used only through webioom's own authenticated server-side workflows

Why webioom doesn't just “let AI edit the site”

For AI-assisted fixes, AI helps prepare the replacement text — like a title or a description — for you to review. That's the extent of its role. AI does not:

  • Choose which website resource gets edited
  • Choose arbitrary fields to change
  • Decide what permissions it has
  • Receive your connected credentials
  • Directly execute the supported write itself

After a supported change is applied

1. Verify

webioom attempts a targeted check of the applied change, where verification is available.

2. Record

A successful write is recorded in your history, so you can see exactly what changed.

3. Undo

Where the change is supported and safe to reverse, you can undo it.

4. Re-check

Undo itself re-checks the current state before writing anything — never a blind reversal.

webioom does not currently hold formal certifications such as SOC 2, ISO 27001, or similar, and has not undergone third-party security audits or penetration testing. This page describes the product's design principles, not a compliance or certification claim.