Scoped connection keys
The connector authenticates with a rotating scoped key, never your administrator password. Keys are unique per site, revocable from either end, and rotated automatically on a schedule.
You are handing us the ability to change every site you are responsible for. That deserves a specific answer rather than a padlock icon, so this page describes exactly how the connection, the credentials and the data are handled.
Signed DPA available on any paid plan.
Updated
The connector authenticates with a rotating scoped key, never your administrator password. Keys are unique per site, revocable from either end, and rotated automatically on a schedule.
TLS 1.3 for every connection. AES-256 for backups and stored credentials at rest, with encryption keys held in a separate key management service rather than alongside the data.
Team members receive the narrowest role that lets them work. Elevated actions require explicit permission, and every one is attributed and logged.
Operational data and backups are stored in the United States on OVHcloud servers, and you can keep backups in your own storage instead.
Append-only logging of every action on every site. Entries cannot be edited or deleted through the interface by anyone, including account owners.
Customer data is logically isolated at every layer. Backup storage, operational data and job execution are separated per account.
Infrastructure and application monitoring with alerting on anomalous access patterns, failed authentication clusters and unexpected privilege use.
Download your backups, leads, chat history and activity logs from your dashboard at any time. No exit fee and no retention hold.
WPCentrify is operated by a company incorporated in Pakistan, which is the contracting entity for all WPCentrify services, the data controller for account data and the data processor for customer site data. Its full legal name is set out in our Terms of Service, Privacy Policy and Data Processing Agreement.
Jurisdiction of incorporation: Pakistan
Registered address: PVT CENTER CHAKLALA, RAWALPINDI, Pakistan
Security contact: security@wpcentrify.com
Buyers evaluating a data processing agreement generally need the operating entity and its jurisdiction on record before procurement can proceed. The jurisdiction is stated here, and the full legal details are in the documents linked above, ready for procurement review.
The WPCentrify connector is a small WordPress plugin. It exposes an authenticated endpoint that accepts signed instructions from the platform and performs the requested operation. Specifically:
Monitoring requests come from outside the site entirely and do not depend on the connector, which is why availability monitoring continues to work when a site is failing.
Two-factor authentication is available on every account and can be enforced across a team. SAML single sign-on and SCIM provisioning are supported, so account lifecycle follows your identity provider. Sessions expire on inactivity, all sessions can be revoked centrally, and one-click logins into WordPress are recorded as attributable sessions rather than disappearing into wp-admin.
We welcome good-faith security research. Report findings to security@wpcentrify.com. We acknowledge within one business day, provide a substantive response within five, and will not pursue legal action against research conducted in good faith that avoids privacy violations, service degradation and data destruction. Researchers are credited publicly where they want that.
Our subprocessors are limited to infrastructure and operational service providers, each listed in the data processing agreement along with their function and processing location. Customers are notified in advance of any new subprocessor and may object. Standard contractual clauses are available for international transfers, and our GDPR commitments set out the lawful basis, data subject rights and retention positions in full.
Certification note: formal certification status should be stated here once audits complete. Do not claim a certification the company does not hold.
The connector plugin authenticates using a rotating scoped key rather than your WordPress administrator password. That key grants the specific capabilities the platform needs: reading site state, applying updates, taking backups and running health checks. It can be revoked from your WordPress installation or from the WPCentrify dashboard at any moment, from either end.
No. We never ask for or store WordPress administrator credentials. One-click login works through short-lived cryptographically signed tokens that are valid for seconds and cannot be reused.
Operational data and backups are stored in the United States on OVHcloud servers. Using your own S3-compatible bucket, so backups never leave infrastructure you control, is planned.
We operate an incident response process with defined severity levels and notification commitments. Affected customers are notified without undue delay and in any case within 72 hours of confirmation, with the facts as known, the scope, and the specific actions taken. Connection keys can be rotated across an entire portfolio in a single action.
Yes. A signed data processing agreement is available on request for any paid plan, and standard contractual clauses are available for international transfers. See the DPA.
Yes, and we would be grateful. Email security@wpcentrify.com with the detail. We acknowledge within one business day, do not pursue legal action against good-faith research, and credit reporters publicly where they want that.
We will complete your security questionnaire, provide a signed DPA and walk your team through the architecture. That is a normal request and we treat it as one.
Free during early access. Keep your data, export any time.