Skip to main content
haplo.online
Terms Privacy Cookies Security DPA Sub-processors Contact
Test Haplo beta
Security

Security and CMS access

How Haplo handles CMS credentials, beta access, draft-first publishing and content workflow data.

Last updated: 30 June 2026

CMS access principles

Haplo is designed so beta users do not need to share their main CMS password. Use a dedicated, revocable token or Application Password for Haplo.

  • WordPress: use a named Application Password for Haplo.
  • Webflow: use the minimum CMS permissions needed for draft item creation.
  • Shopify: use a dedicated Admin API token with the content-writing scope needed for draft article creation.
  • Sanity: use the minimum project/dataset write access needed for the selected document type.

What Haplo stores

Haplo uses API tokens, usernames and passwords for the current request only. The backend does not store API tokens, usernames or passwords.

Haplo may process and retain content workflow data needed to operate the beta, such as keywords, competitor information, SERP data, prompts, brand guidance and generated drafts.

Safe beta checklist

  • Use draft mode while testing.
  • Use a dedicated token with the least permissions needed.
  • Revoke tokens after testing if they are no longer needed.
  • Do not paste private customer data, regulated data, personal secrets or confidential information unless you are authorised to do so.
  • Review content before publishing.

Reporting a security issue

Send security concerns to info@stringerseo.co.uk. Include the affected URL, a short description and steps to reproduce where safe to do so.

Haplo is a product owned and operated by STRINGERSEO Limited.

STRINGERSEO Limited is registered in England & Wales. Company number: 12087401. Registered office: Hallam Way, Whitehills Business Park, Blackpool, FY4 5FS, England.

Contact: info@stringerseo.co.uk

Terms Privacy Cookies Security DPA Sub-processors Contact

© 2026 Haplo Online

Cookies and analytics

Haplo uses essential cookies only by default. Analytics and third-party embeds are only loaded when you accept non-essential cookies or choose to load a specific third-party form.