Security and CMS access
How Haplo handles CMS credentials, beta access, draft-first publishing and content workflow data.
Last updated: 30 June 2026
CMS access principles
Haplo is designed so beta users do not need to share their main CMS password. Use a dedicated, revocable token or Application Password for Haplo.
- WordPress: use a named Application Password for Haplo.
- Webflow: use the minimum CMS permissions needed for draft item creation.
- Shopify: use a dedicated Admin API token with the content-writing scope needed for draft article creation.
- Sanity: use the minimum project/dataset write access needed for the selected document type.
What Haplo stores
Haplo uses API tokens, usernames and passwords for the current request only. The backend does not store API tokens, usernames or passwords.
Haplo may process and retain content workflow data needed to operate the beta, such as keywords, competitor information, SERP data, prompts, brand guidance and generated drafts.
Safe beta checklist
- Use draft mode while testing.
- Use a dedicated token with the least permissions needed.
- Revoke tokens after testing if they are no longer needed.
- Do not paste private customer data, regulated data, personal secrets or confidential information unless you are authorised to do so.
- Review content before publishing.
Reporting a security issue
Send security concerns to info@stringerseo.co.uk. Include the affected URL, a short description and steps to reproduce where safe to do so.