Product
Solutions
Compare
Resources
Get early access Talk to us
Security

How WPCentrify protects the sites you connect

You are handing us the ability to change every site you are responsible for. That deserves a specific answer rather than a padlock icon, so this page describes exactly how the connection, the credentials and the data are handled.

Signed DPA available on any paid plan.

Design

Security architecture

Scoped connection keys

The connector authenticates with a rotating scoped key, never your administrator password. Keys are unique per site, revocable from either end, and rotated automatically on a schedule.

Encryption everywhere

TLS 1.3 for every connection. AES-256 for backups and stored credentials at rest, with encryption keys held in a separate key management service rather than alongside the data.

Least privilege by default

Team members receive the narrowest role that lets them work. Elevated actions require explicit permission, and every one is attributed and logged.

Regional data residency

Choose where operational data and backups live. EU-only residency is available, and you can bring your own storage bucket.

Tamper-evident audit trail

Append-only logging of every action on every site. Entries cannot be edited or deleted through the interface by anyone, including account owners.

Isolation between tenants

Customer data is logically isolated at every layer. Backup storage, operational data and job execution are separated per account.

Continuous monitoring

Infrastructure and application monitoring with alerting on anomalous access patterns, failed authentication clusters and unexpected privilege use.

Exit without friction

Complete export of sites, clients, history and backups at any time. No exit fee, no retention hold, no negotiation.

Operating entity and jurisdiction

WPCentrify is operated by CentriQor, the contracting entity for all WPCentrify services and the data controller of record for account data and the data processor for customer site data.

Legal entity: CentriQor
Jurisdiction of incorporation: [JURISDICTION PLACEHOLDER] (placeholder, to be completed)
Registered address: [REGISTERED ADDRESS PLACEHOLDER] (placeholder, to be completed)
Security contact: security@wpcentrify.com

Buyers evaluating a data processing agreement generally need the operating entity and its jurisdiction on record before procurement can proceed. Both are stated here deliberately rather than buried in the terms.

How the connector works

The WPCentrify connector is a small WordPress plugin. It exposes an authenticated endpoint that accepts signed instructions from the platform and performs the requested operation. Specifically:

  • It performs no work during front-end page loads and adds nothing to the rendered page for visitors.
  • It accepts instructions only from our infrastructure, verified by signature against a key unique to that site.
  • It never transmits customer personal data except as part of a backup you have configured.
  • It can be deactivated from within WordPress at any time, which immediately and completely severs platform access to that site.

Monitoring requests come from outside the site entirely and do not depend on the connector, which is why availability monitoring continues to work when a site is failing.

Access control and authentication

Two-factor authentication is available on every account and can be enforced across a team. SAML single sign-on and SCIM provisioning are supported, so account lifecycle follows your identity provider. Sessions expire on inactivity, all sessions can be revoked centrally, and one-click logins into WordPress are recorded as attributable sessions rather than disappearing into wp-admin.

Vulnerability disclosure

We welcome good-faith security research. Report findings to security@wpcentrify.com. We acknowledge within one business day, provide a substantive response within five, and will not pursue legal action against research conducted in good faith that avoids privacy violations, service degradation and data destruction. Researchers are credited publicly where they want that.

Subprocessors and compliance

Our subprocessors are limited to infrastructure and operational service providers, each listed in the data processing agreement along with their function and processing location. Customers are notified in advance of any new subprocessor and may object. Standard contractual clauses are available for international transfers, and our GDPR commitments set out the lawful basis, data subject rights and retention positions in full.

Certification note: formal certification status should be stated here once audits complete. Do not claim a certification the company does not hold.

Answers

Security questions

The connector plugin authenticates using a rotating scoped key rather than your WordPress administrator password. That key grants the specific capabilities the platform needs: reading site state, applying updates, taking backups and running health checks. It can be revoked from your WordPress installation or from the WPCentrify dashboard at any moment, from either end.

No. We never ask for or store WordPress administrator credentials. One-click login works through short-lived cryptographically signed tokens that are valid for seconds and cannot be reused.

Operational data and backups are stored in the region you select. Regional residency is configurable, including EU-only storage. You can supply your own S3-compatible bucket so backups never leave infrastructure you control.

No. Customer site content, backups, credentials and operational data are never used to train models, never sold, and never shared with third parties for their own purposes. Our subprocessors are listed in the DPA and are limited to infrastructure and operational services.

We operate an incident response process with defined severity levels and notification commitments. Affected customers are notified without undue delay and in any case within 72 hours of confirmation, with the facts as known, the scope, and the specific actions taken. Connection keys can be rotated across an entire portfolio in a single action.

Yes. A signed data processing agreement is available on request for any paid plan, and standard contractual clauses are available for international transfers. See the DPA.

Yes, and we would be grateful. Email security@wpcentrify.com with the detail. We acknowledge within one business day, do not pursue legal action against good-faith research, and credit reporters publicly where they want that.

Early access open

Need a security review before you connect?

We will complete your security questionnaire, provide a signed DPA and walk your team through the architecture. That is a normal request and we treat it as one.

Free during early access. Keep your data, export any time.