Encryption
- API keys you store in RankZap are encrypted at rest with AES-256-GCM.
- OAuth tokens for Google and Bing are encrypted at rest.
- The public application uses HTTPS. Supported provider integrations use HTTPS; public pages submitted for an audit may themselves use HTTP.
- Passwords are never stored in the clear. We store a bcrypt hash and compare against it at sign-in.
Access control
- Every client, report and connection lives inside a workspace. Data from one workspace is not visible to another.
- Workspaces have four roles: owner, admin, member and viewer. Each role sees and changes only what it needs to.
- Within RankZap, access to production systems is limited to the founder and the engineers who need it to do their job.
Google and Bing data
Connected data is read only after you authorise it and only for the properties you choose. It is used only for the reporting you requested, never sold, never used for advertising, and never used to train AI models. Our use of Google data follows the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect from Settings at any time, or revoke access at myaccount.google.com/permissions.
Backups and retention
We retain account and workspace data while needed to provide the service. To request deletion or a data export, email hello@rankzapseo.com from your account address. We verify the request and respond within the time required by applicable law. We delete or anonymise data that is no longer needed, except records we must retain for billing, security, disputes or legal obligations. Backup copies may remain until their normal rotation; they are not used for routine processing, and deletion requests must be reapplied if a backup is restored. Contact us for the retention arrangements applicable to your data.
Infrastructure
RankZap runs on DigitalOcean in the Bangalore region, with MongoDB Atlas as the database. The full list of providers, and what each one receives, is in the Privacy notice.
If something goes wrong
If an incident affects your data, we will notify affected customers without undue delay and tell you what happened and what we are doing about it. We will not wait until we have a polished statement.
Being honest about size
RankZap is built by a small team. We do not hold SOC 2 or ISO 27001 certification, and we will not claim to until we do. What we can promise is that the practices above are real, that the list gets longer over time, and that a direct question about security gets a direct answer.
Reporting a security issue
If you find a vulnerability, email hello@rankzapseo.com with enough detail to reproduce it. We read those messages first, we will not take action against good-faith research, and we will tell you when it is fixed.