Security
Your sites, your data, handled carefully
We designed MakeMerge so publishing is boringly safe: nothing deleted by surprise, nothing overwritten quietly, and clear confirmation before anything goes live.
Publishing that doesn’t scare you
Nothing deleted or overwritten
We add pages and content carefully. Your existing WordPress site is not wiped to make room for a push.
Drafts first
New pages arrive as drafts. You review and publish on your schedule — not ours.
Backup before every write
A full backup runs before each push, with one-click rollback if something doesn’t look right.
Three-step publish confirm
Explicit confirmation before anything becomes public. Accidental deploys should be hard.
Connections
Scoped access to your WordPress site
MakeMerge connects with the minimum permissions needed to push drafts and media. Credentials are encrypted at rest. You can revoke access from WordPress whenever you want.
- Scoped connection — not a blank cheque
- Encrypted credential storage
- Revoke from your WordPress admin anytime
Keys, teams, and your content
Bring your own AI key
Use your own provider credentials so generation runs under your account. Your content does not have to touch MakeMerge-held AI keys.
Permissions default to off
Teammates get access you grant — not everything by default. Tighten scopes per person.
Data deletion on request
Need a project or account removed? Ask and we delete the associated MakeMerge data. We’ll confirm when it’s done.
Responsible disclosure
If you find a vulnerability in MakeMerge, tell us privately before publishing it. We take reports seriously and will work with you on a fix timeline.
Email security reports to [email protected]. Include steps to reproduce and impact if you can. Please do not access customer data or disrupt production while testing.
We do not claim SOC 2, ISO, or other certifications we have not earned. This page describes how the product behaves today — not a compliance badge wall.
General support →