Security & privacy

Your site data stays on your site.

Every free check runs on your own server and sends nothing anywhere. The AI audits run only when you run them, and you can read exactly what they send first.

Is BoltAudit safe to run on a production site?

Yes. The Local Audit and the SEO checks are read-only and run entirely on your own server, so nothing is modified while they scan and nothing leaves the site. Fixes apply only when you choose to apply them. Every change is backed up first and reversible in one click from Fix History, and no account is required to start.

One rule, both engines.

BoltAudit's performance engine and its SEO & AEO engine follow the same rule: everything free runs locally, everything AI is opt-in per run. There is no background sending, no analytics reading, and no data leaving your site that you did not start yourself.

On your server
Local Audit
Run SEO Check
All findings
All local fixes

Nothing leaves the site.

Cloud, only when you run it
AI Deep Audit
AI Visibility Audit

You start it, and you see what it sends.

What leaves your site, exactly.

Feature Where it runs What leaves your site
Local Audit Your server Nothing. Reads plugins, database, and environment.
Run SEO Check Your server Nothing. Reads your public pages, robots.txt, and sitemap.
AI Deep Audit Cloud, only when you run it The performance findings being analyzed, listed in the disclosure you can read before it starts.
AI Visibility Audit Cloud, only when you run it Page titles, metas, and the text of analyzed pages, to judge citability and draft fixes.
External crawler probe Cloud, optional One request to your homepage, made the way an AI crawler would. Off by default.
Email alerts Cloud Your email address and the alert numbers you enabled.

That is the complete list. If a feature is not here, it sends nothing.

What happens when you apply a fix.

Preview first

You see exactly what will change, and the evidence for it, before anything happens.

Backup taken

A restore point is captured before any change is written.

Recorded in Fix History

Every change, applied or rolled back, in plain words.

One-click undo

Any applied fix reverses instantly, long after it was made.

AI-drafted content, like meta descriptions, never publishes without your review. There is no setting to skip it.

You hold the switches.

robots.txt editing

On by default so BoltAudit can unblock AI crawlers. Turn it off and those fixes become guided instructions instead.

External crawler probe

Off by default. Turn it on per site if you want an outside check of how your CDN answers AI crawlers.

Your AI key

Stored for your account, used only for the AI audits you run. Remove it any time; credits take over.

Questions about your data

The SEO checks read your public pages on your own server and send nothing. Only the AI Visibility Audit sends page text, and only when you run it.

No. It never connects to your analytics, and it has no access to customer records. Loss figures are research-backed estimates, which is why every one is labeled estimated.

They run in BoltAudit's cloud using your weekly credits or your own AI key. The report comes back to your dashboard; the analyzed text is not used to train anything.

Never. It changes settings and data only, and every change is in Fix History with one-click rollback.

The plugin's tables are removed on uninstall if you enable cleanup in Settings, and nothing remains on your server that you did not keep.

More questions? Visit our FAQ Contact Us

Read-only until you say otherwise.

Install the free plugin and see everything it finds before a single byte leaves your site.

Install the free plugin See how it works