Security & Data
ZoofiAI is designed so an AI receives capabilities through a controlled connection instead of receiving unrestricted WordPress or hosting credentials.
OAuth AI access
Compatible AI clients authorize through ZoofiAI. Access can be revoked without sharing your WordPress password with the AI.
Per-site routing
Multi-site requests are tied to an explicit connected site so one site's actions do not silently target another site.
Permission profiles
Read-only, content, developer, site-manager and custom controls can limit what an AI connection is allowed to request.
Approvals & checkpoints
Higher-risk operations can use previews, approval tokens, audit trails, backups or checkpoints before execution.
Secrets
Do not paste WordPress passwords, API keys, OAuth tokens, database passwords, Cloudflare tokens or payment secrets into ordinary AI messages. Use supported server-side or ZoofiAI secure settings for secrets.
Audit and revocation
ZoofiAI records security and action metadata for supported workflows and provides controls to revoke AI grants or disconnect sites. Organization controls can further restrict sensitive operations.
Third-party AI providers
Your chosen AI provider has its own security, privacy and retention rules. Review the provider's settings and permissions before connecting ZoofiAI.
Report a security concern
Email support@zoofiai.com with a clear description and reproduction details. Do not include active credentials in the report.