Trust Centre

Security, privacy and compliance.

How CiteRank protects customer data across AI visibility measurement — what is in place today, what is in progress, and what is planned. Every capability below carries an explicit status.

01 — Overview

Security overview

CiteRank is a monitoring platform: we send prompts to supported AI engines, capture the answers those engines return, and analyse how brands appear in them. The data we hold is primarily configuration (brands, competitors, prompts), captured engine responses, and workspace account records. We do not require customer end-user databases, payment card data or health records to deliver the service, and we ask customers not to upload them.

Tenant isolation

Workspace data is logically isolated so one workspace cannot read another workspace's runs, prompts or reports.

Least-privilege access

Access to production data by CiteRank personnel is restricted to the staff who need it for support or operations.

Dependency scanning

Automated dependency and platform vulnerability scanning runs against the CiteRank codebase.

Authenticated access

All customer data sits behind authenticated sessions and row-level authorisation rules.

02 — Encryption

Encryption

Encryption in transit

All traffic between browsers, our application and our infrastructure is served over HTTPS with modern TLS. HSTS is enabled on the production domain.

Available
Encryption at rest

Databases, object storage and backups are encrypted at rest by the underlying managed cloud platform.

Available
Customer-managed keys (BYOK)

Bring-your-own-key encryption is not offered today. Contact us if this is a procurement requirement.

Available
03 — Hosting

Hosting

CiteRank runs on managed cloud infrastructure rather than self-operated hardware. The web application is served from an edge/worker runtime with provider-level DDoS protection, and application data is stored in a managed Postgres platform with managed authentication. Physical and environmental controls are inherited from those providers.

Application layer

Edge/worker runtime, autoscaled by the platform provider.

Data layer

Managed Postgres with managed authentication and automated backups.

Delivery

Global CDN with TLS termination and provider DDoS mitigation.

04 — Subprocessors

Subprocessors

We use third-party subprocessors to deliver the service. The categories below reflect current production use. The current named subprocessor list, including entity names and processing locations, is provided on request and attached to the DPA — email security@citerank.in.

CategoryPurposeData involved
Cloud hosting & CDNApplication delivery and computeRequest metadata, session data
Managed database & authStorage of workspace, prompt and run dataAccount records, monitoring data
AI engine providersExecuting monitoring prompts and replaysPrompt text submitted for monitoring
Email deliveryTransactional and report emailsName, work email address
Product analyticsUsage analytics behind a consent gatePseudonymous usage events
Payment processingSubscription billingBilling contact and invoice data

Customers under a signed DPA are notified of material subprocessor changes before they take effect.

05 — Data locations

Data locations

Default hosting region

Workspace data is stored in the region configured for your account at provisioning. We confirm the exact region in writing before contract signature.

Available
Regional residency (EU / US / India)

Region selection is handled per enterprise agreement rather than self-serve. Confirm the region with sales before signing — do not assume a region is available.

Contact us
AI engine processing locations

Prompts sent to third-party AI engines are processed in the regions those providers operate. We cannot offer a commitment for in-region processing for external engines.

Contact us
06 — Retention

Retention

Monitoring data is retained for as long as your workspace is active, because historical runs are what make trend analysis possible. Retention windows for specific data classes, including shorter windows for regulated customers, are agreed in the contract.

Active workspaces

Prompts, runs, captured answers and reports are retained while the subscription is active so historical comparisons remain valid.

Deletion on request

Workspace owners can request deletion of their workspace data. We action verified deletion requests and confirm completion in writing.

Backups

Encrypted backups are held by the managed database platform on a rolling window; deleted records age out with that cycle.

Legal holds

We retain records where required by law or to resolve a dispute, and only for as long as that requirement lasts.

07 — Privacy

Privacy

The personal data we process is limited to workspace account data — names, work email addresses, role assignments and usage events. Monitoring prompts are business questions about brands and categories, not personal data, and customers are asked not to include personal data in them. Product analytics run behind a consent gate. Full detail is in the Privacy Policy and the privacy documentation.

Data subject requests

Access, correction, export and erasure requests can be sent to privacy@citerank.in. We acknowledge requests and respond within the statutory period applicable to the requester.

08 — DPA

Data Processing Addendum

CiteRank acts as processor for customer workspace data and offers a standard Data Processing Addendum covering processing scope, subprocessor notification, security measures, international transfer mechanisms and assistance with data subject requests.

09 — Disclosure

Vulnerability disclosure

We welcome reports from security researchers. Send findings to security@citerank.in with reproduction steps and the affected URL. Please give us reasonable time to remediate before public disclosure, do not access or modify other customers' data, and do not run denial-of-service or high-volume automated testing against production.

Acknowledgement

We acknowledge valid reports within 3 business days.

Triage

We confirm severity and expected remediation timeline after reproduction.

Safe harbour

Good-faith research within these rules will not trigger legal action from us.

We do not currently operate a paid bug bounty programme.

10 — Incidents

Incident management

Suspected security incidents are triaged by the engineering team on receipt. Our process is detect and contain, assess scope and affected workspaces, remediate, then notify. Where a personal data breach affecting customer data is confirmed, we notify affected customers without undue delay and within the timelines set out in the DPA.

Operational availability is published on the status page, which is maintained manually and is not an automated telemetry feed. Customer-impacting incidents are communicated directly to affected workspaces by email.

11 — Status

Certification status

In Progress

SOC 2 Type II audit in progress

SOC 2 Type II audit in progress. We follow SOC 2 aligned controls across our organisation and infrastructure. Reports are available during Enterprise security review.

Available

GDPR & DPDP alignment

We operate under a DPA aligned to the EU GDPR and India's Digital Personal Data Protection Act. Alignment is a contractual and operational commitment.

Planned

ISO/IEC 27001

Alignment with ISO 27001 standards is on the compliance roadmap after SOC 2.

Contact us

Penetration testing

Independent penetration-testing evidence is available during Enterprise security review where applicable. Contact security for the latest assessment status.

12 — Continuity

Business continuity

Backups

Application data is backed up automatically by the managed database platform, with encrypted point-in-time recovery within the provider's retention window.

Recovery

Infrastructure is reproducible from version-controlled configuration, so the application layer can be redeployed without manual rebuild.

Recovery objectives

Formal RTO and RPO commitments are agreed per enterprise contract rather than published as a blanket commitment.

Provider dependency

Continuity depends on our cloud and AI engine providers. An outage at an engine provider pauses affected monitoring runs; they resume when the provider recovers.

13 — AI providers

AI provider data handling

Monitoring works by sending prompts to third-party AI engines and capturing what they return. This is the part of the service most often reviewed in security assessments.

  • What we send: the monitoring prompt text you configure — category and brand questions such as "best enterprise AI visibility platforms". We do not send your customer records, uploaded documents or workspace credentials to AI engines.
  • What we receive and store: the engine's answer text, cited sources and run metadata, so results can be compared over time.
  • Where it is processed: inside each provider's own infrastructure, under that provider's terms. We use business/API tiers where available rather than consumer endpoints.
  • Training: we do not authorise our providers to use customer prompt content to train foundation models where the provider's API terms allow opt-out.
  • What we cannot control: an external AI engine's own retention, logging and abuse-monitoring behaviour. If your assessment requires provider-level commitments, request our current provider terms summary.
14 — Review

Enterprise Security Review

Request Security Pack

For enterprise procurement, we provide a complete security review pack including our latest independent assessments, network architecture diagrams, and internal security policies.

Request Security Documentation

Note: Independent penetration-testing evidence and SOC 2 status updates are available during Enterprise security review where applicable. Contact security for the latest assessment status.

Have a security question?

Our team completes vendor questionnaires, security assessments and procurement reviews. If a control you need is not listed above, assume it is not in place and ask us.

Run Free Audit