Skip to content50% off your first yearClaim 50% off
AutoSEO

AutoSEO for organizations

AI visibility for organizations that need control

Track how ChatGPT, Perplexity, Gemini, Claude and Google's AI features describe every brand and market you own — on your own servers under the MIT license, or in AutoSEO Cloud, hosted in Germany.

Deployment

Two ways to run it. One codebase.

AutoSEO Cloud runs exactly the open-source app you can install yourself. Choose by who should operate it, not by features.

  • Free · MIT

    Self-hosted in your infrastructure

    Run AutoSEO on your own Linux server with Docker Compose, the one-line installer or Coolify. Your database, your backups, your network rules: data stays where you deploy it, apart from requests to the AI and SEO data providers you configure. Every feature, no limits on users, projects or prompts.

  • $50/month

    AutoSEO Cloud, hosted in Germany

    Your own workspace in our fully managed AutoSEO. AI providers, SEO data and email are managed by us (no API keys needed), updates are automatic and $10 of provider usage per month is included. Unlimited users and up to 10 projects per workspace. Compare plans.

Security

Security controls that ship with the product

No add-on tier: these controls are part of the open-source code, so your security team can read exactly how they work.

ControlWhat it doesSelf-hostedAutoSEO Cloud
Encrypted secretsProvider API keys, SMTP credentials and OAuth client secrets are encrypted at rest with AES-256-GCM.✓ Key lives in your data volume✓ Managed by us
Hashed tokensAPI keys, OAuth tokens and local-agent tokens are stored only as SHA-256 hashes; the plaintext is shown once.✓✓
Passwordless sign-inInvite-only magic links and one-time codes. Sessions use __Host- cookies (Secure, HttpOnly, SameSite=Lax) and can be revoked per device.✓✓
Email-domain allow-listRestrict sign-ins to your company domains, enforce invite-only mode, set session length and device limits.✓ Admin → AuthenticationInstance-wide policy set by us
Roles & per-project accessOwner, Admin, Member and Client roles. Members and clients only see the projects they are assigned to.✓ Plus custom roles (Admin → Roles)✓ Assign existing roles and project access
Audit logRecords sign-ins (including denied ones), invitations, role changes, API keys, integrations and exports; exportable.✓ Admin → Audit LogKept by us as instance operator
SSRF protectionRequests triggered by integrations (webhooks, crawling, publishing) cannot reach private or LAN addresses unless an admin allows a specific host.✓ Allow specific intranet hosts✓ No internal hosts
GDPR export & erasureEvery user can download their personal data and delete their account; admins can erase users.✓✓
Scoped API keysKeys are limited to the scopes read, write, spend and export, and to all or selected projects.✓✓
OAuth 2.1 for MCPAI assistants connect to the MCP server through OAuth 2.1 instead of shared static keys.✓✓
Signed agent updatesLocal agents open no inbound ports, talk to your instance over outbound HTTPS and verify signed releases before updating.✓✓

Found a vulnerability? Report it privately via GitHub Security Advisories or security@codext.de, as described on our security page.

Control

Who controls what

Self-hosted, you are the instance admin and control everything. On AutoSEO Cloud, you own your workspace, while instance-wide settings are operated by us.

AreaSelf-hostedAutoSEO Cloud
Members, invitations, role assignment, per-project accessYouYou, as workspace owner
Projects, prompts, competitors, engines, reportsYouYou
DataForSEO accountYou — for the instance (Admin → Data Providers) or per workspaceManaged by us; you can connect your own account for your workspace
Custom rolesYou (Admin → Roles)Defined by the instance operator; you assign the available roles
Audit logYou (Admin → Audit Log)Kept by us as instance operator
Email-domain allow-list, invite-only mode, session policyYou (Admin → Authentication)Instance-wide policy set by us
AI providers, email delivery, limits and budgetsYou (admin panel)Managed and operated by us

Multi-brand, multi-region

Mirror your organization: workspaces, projects, roles

Subsidiaries, brands, markets and clients map onto two building blocks. Access follows the same structure.

  • Workspaces

    A workspace is a team boundary with its own members, roles, integrations and API keys. Use one per business unit, subsidiary or client group.

  • Projects per brand and market

    A project is one website or brand with its own prompts, competitors, engines and market (country and language). Track the same brand in Germany and the US as two projects.

  • Per-project access

    Owners and Admins see every project in their workspace. Members and read-only Clients see only the projects they are given — ideal for regional teams and agencies.

  • Portfolio overview

    Key AI-visibility metrics for all your projects in one table — visibility and its trend, share of voice, average position, sentiment, citations, open high-impact tasks and AI revenue — so central teams keep the overview across brands and markets.

  • White-label reports

    The report builder uses brand kits with your logo and colors, exports PPTX and PDF and creates password-protected share links. See the report builder.

  • API, MCP and exports

    A REST API with OpenAPI spec, an MCP server for AI assistants and CSV or Google Sheets exports feed your own dashboards. REST API · MCP server · guides for Claude and ChatGPT.

For IT and platform teams

What running AutoSEO yourself involves

Self-hosting is deliberately boring: one container image, one database and settings in an admin panel.

  • One Docker image (ghcr.io/codextde/autoseo) plus PostgreSQL 17 — no other runtime services required
  • Only the domain and database live in environment variables; everything else is configured in the admin panel
  • Database migrations run automatically at boot, so an update is a redeploy
  • Works behind your reverse proxy (Traefik, nginx, Cloudflare Tunnel) or with the bundled Caddy for automatic HTTPS
  • Daily and monthly spend caps for AI and SEO data providers
  • AI through your own Claude Code or Codex subscriptions via local agents, or through your own API keys
  • Source code you can audit, fork and extend under the MIT license

Sizing

2 vCPU and 2–4 GB RAM are enough for small teams. Scale up if you run large site audits or heavy keyword and backlink jobs.

Back up two volumes

The PostgreSQL volume and the data volume, which holds uploads and the encryption key for stored secrets. Without that key, stored provider credentials cannot be decrypted.

Read the self-hosting guide →

Procurement

The facts your procurement team will ask for

We would rather tell you plainly where AutoSEO stands than show you a wall of badges:

  • Vendor: Codext GmbH, Frankenstraße 10, 74549 Wolpertshausen, Germany (Amtsgericht Stuttgart, HRB 772091).
  • License: MIT. Running AutoSEO in your own infrastructure requires no contract with us.
  • AutoSEO Cloud hosting: servers in Germany.
  • Data processing agreement (Cloud): available on request under Art. 28 GDPR — email kontakt@codext.de.
  • Certifications: we do not claim SOC 2 or ISO 27001 certification for AutoSEO Cloud. If your policy requires one, run AutoSEO inside your own certified environment.
  • Vulnerability handling: private disclosure, acknowledgement within two business days, see SECURITY.md.
  • Billing (Cloud): $50 per workspace and month via Stripe, with an invoice for every payment; cancel anytime.

Questions from organizations

Where is our data stored?

When you self-host, all data stays in the PostgreSQL database and data volume on your own server, wherever you run it. AutoSEO only sends the request data needed for a feature — for example tracked prompts, brand and competitor names, domains and keywords — to the AI and SEO data providers you configure. AutoSEO Cloud runs on servers in Germany.

Do you sign a data processing agreement?

For AutoSEO Cloud, yes: we process personal data in your workspace as a processor under Art. 28 GDPR and provide a data processing agreement on request — email kontakt@codext.de. When you self-host, we do not process your data at all, so no agreement with us is needed; you still need agreements with the AI and data providers you connect.

Is AutoSEO SOC 2 or ISO 27001 certified?

We do not claim either certification for AutoSEO Cloud. What we offer instead is transparency: the complete source code is public, the security model is documented in SECURITY.md, and you can run AutoSEO inside your own certified infrastructure, where your existing controls apply.

Can we use single sign-on with SAML or OpenID Connect?

Not today. AutoSEO uses passwordless sign-in with invite-only magic links and one-time codes. On a self-hosted instance you can restrict sign-ins to your company email domains, enforce invite-only mode and limit session length and devices. If SAML or OIDC is a hard requirement for you, tell us — or contribute it on GitHub.

How do we manage many brands, regions or clients?

Create a workspace per business unit or client group and a project per brand and market, each with its own prompts, competitors, engines, country and language. Members and clients only see the projects they are assigned to, and the portfolio overview shows key AI-visibility metrics for all your projects in one table (visibility and its trend, share of voice, average position, sentiment, citations, open high-impact tasks and AI revenue). AutoSEO Cloud includes up to 10 projects per workspace; self-hosted AutoSEO has no project limit.

How do we keep AI and data costs under control?

When you self-host, providers such as DataForSEO and your AI provider bill you directly, and AutoSEO enforces daily and monthly spend caps. You can also route AI work through Claude Code or Codex subscriptions you already pay for, via the local agent. AutoSEO Cloud includes $10 of provider usage per workspace and month under fair use, and workspace owners can connect their own DataForSEO account.

Can we get a custom contract, annual invoice or purchase order?

AutoSEO Cloud is billed monthly via Stripe, with an invoice for every payment. If your organization needs different terms, email info@codext.de with your requirements and we will tell you what is possible. Self-hosting under the MIT license needs no contract at all.

Can our security team review the code before we roll it out?

Yes. The full source code of the app, the local agent and the deployment files is on GitHub under the MIT license. Please report any vulnerability privately via GitHub Security Advisories or security@codext.de rather than in a public issue.

Plan your rollout with us

Tell us about your brands, markets and security requirements, and we will help you choose between self-hosting and AutoSEO Cloud.

Claim 50% off