Security at RankRight

Last reviewed September 6, 2026 · This page describes the controls actually in place today. It is written to answer the questions security questionnaires ask; if yours asks something it doesn’t cover, ask us.

  1. Summary
  2. Hosting and data residency
  3. Encryption in transit
  4. Encryption at rest and secrets
  5. Authentication and sessions
  6. Tenant isolation and access control
  7. API, MCP and webhook security
  8. AI providers and third parties
  9. Retention, backups and deletion
  10. Operations and monitoring
  11. Incident response
  12. Vulnerability disclosure
  13. Compliance status
  14. Contact

1. Summary

2. Hosting and data residency

The application and its database run on a virtual private server operated by WHG Hosting Services in Dallas, Texas, USA, fronted by Cloudflare for DNS, TLS termination, DDoS protection and caching of public pages only. Customer data is stored and processed in the United States. We do not currently offer regional hosting outside the US.

3. Encryption in transit

All traffic to rankright.dev and app.rankright.dev is served over HTTPS (TLS 1.2+); HTTP requests are redirected. The origin server holds its own Let’s Encrypt certificates, so traffic is encrypted between Cloudflare and the origin as well as between you and Cloudflare. Strict-Transport-Security (one year, including subdomains), X-Frame-Options: DENY, X-Content-Type-Options: nosniff and a Content Security Policy are set on application responses. Calls to third-party providers (AI, ranking data, Stripe, Google) are made over TLS.

4. Encryption at rest and secrets

5. Authentication and sessions

6. Tenant isolation and access control

7. API, MCP and webhook security

8. AI providers and third parties

AI features send workspace content to Anthropic, OpenAI, Google (Gemini) and fal.ai under their API terms, which exclude API data from model training. Ranking data comes from DataForSEO and SerpAPI; payments from Stripe (we never see full card numbers). The full sub-processor list, with locations, is in the Privacy Policy. AI-engine observation for the AI Visibility feature asks public questions about businesses; no customer personal data is included.

9. Retention, backups and deletion

10. Operations and monitoring

11. Incident response

If we confirm a security incident affecting your data we will notify the owners of affected organizations by email within 72 hours of confirmation, describe what happened, what data was involved, what we have done, and what we recommend you do. We keep an internal record of incidents and their remediation.

12. Vulnerability disclosure

We welcome reports from security researchers. Email [email protected] with steps to reproduce; you will get an acknowledgement within 3 business days. Please do not access data that is not yours, degrade the service, or disclose publicly before we have had a reasonable chance to fix the issue. We will not pursue legal action against good-faith research that follows these rules. A machine-readable version of this policy is at /.well-known/security.txt. We do not currently run a paid bounty program.

13. Compliance status

RankRight has not pursued SOC 2 or ISO 27001 certification; as a small, focused product we prioritise the concrete controls above over audit reports. We answer security questionnaires and can sign a data-processing agreement on request. See the Privacy Policy for GDPR, UK GDPR and CCPA/CPRA commitments.

14. Contact

Security questions, questionnaires and reports: [email protected]