Encrypted provider secrets
Saved API credentials are encrypted locally and are not re-displayed after they are stored.

PressAI is designed so administrators can see who may act, which external services are configured and where human review remains required.
Saved API credentials are encrypted locally and are not re-displayed after they are stored.
Access can be separated across sources, AI, search, publishing, automation, integrations and other operational areas.
External requests use URL, redirect, response-size, media and webhook safeguards appropriate to the integration.
PressAI contacts external providers only when you configure and use the corresponding source, AI or search integration.
Publishing actions remain subject to workflow state, permissions and the operating mode your team selects.
Your WordPress content remains part of your site and editorial operation. PressAI organizes the workflow around it.
Most PressAI workflow state is handled inside WordPress. Data leaves your site only when a configured feature must contact an external service.
Source monitoring, evidence, AI-assisted editorial processing, review gates, search preparation, queue visibility and governed publishing actions.
Hosting, backups, server administration, WordPress/core/plugin/theme maintenance and broader infrastructure security remain separate responsibilities.
Evidence conflicts, Fact Guard decisions, quality blockers, queue failures and source health are surfaced for review instead of being silently hidden behind automation.
Critical contradictions are surfaced for editorial review rather than auto-resolved.
Failed jobs, retries and source health remain visible so teams can diagnose the workflow.
Readiness and permissions remain part of the decision before draft, schedule or publish actions execute.
Use the security, data-safety and team-access guides to decide how PressAI should operate on your site.