Security, privacy and compliance.
How CiteRank protects customer data across AI visibility measurement — what is in place today, what is in progress, and what is planned. Every capability below carries an explicit status.
Security overview
CiteRank is a monitoring platform: we send prompts to supported AI engines, capture the answers those engines return, and analyse how brands appear in them. The data we hold is primarily configuration (brands, competitors, prompts), captured engine responses, and workspace account records. We do not require customer end-user databases, payment card data or health records to deliver the service, and we ask customers not to upload them.
Tenant isolation
Workspace data is logically isolated so one workspace cannot read another workspace's runs, prompts or reports.
Least-privilege access
Access to production data by CiteRank personnel is restricted to the staff who need it for support or operations.
Dependency scanning
Automated dependency and platform vulnerability scanning runs against the CiteRank codebase.
Authenticated access
All customer data sits behind authenticated sessions and row-level authorisation rules.
Encryption
All traffic between browsers, our application and our infrastructure is served over HTTPS with modern TLS. HSTS is enabled on the production domain.
AvailableDatabases, object storage and backups are encrypted at rest by the underlying managed cloud platform.
AvailableBring-your-own-key encryption is not offered today. Contact us if this is a procurement requirement.
AvailableHosting
CiteRank runs on managed cloud infrastructure rather than self-operated hardware. The web application is served from an edge/worker runtime with provider-level DDoS protection, and application data is stored in a managed Postgres platform with managed authentication. Physical and environmental controls are inherited from those providers.
Application layer
Edge/worker runtime, autoscaled by the platform provider.
Data layer
Managed Postgres with managed authentication and automated backups.
Delivery
Global CDN with TLS termination and provider DDoS mitigation.
Subprocessors
We use third-party subprocessors to deliver the service. The categories below reflect current production use. The current named subprocessor list, including entity names and processing locations, is provided on request and attached to the DPA — email security@citerank.in.
| Category | Purpose | Data involved |
|---|---|---|
| Cloud hosting & CDN | Application delivery and compute | Request metadata, session data |
| Managed database & auth | Storage of workspace, prompt and run data | Account records, monitoring data |
| AI engine providers | Executing monitoring prompts and replays | Prompt text submitted for monitoring |
| Email delivery | Transactional and report emails | Name, work email address |
| Product analytics | Usage analytics behind a consent gate | Pseudonymous usage events |
| Payment processing | Subscription billing | Billing contact and invoice data |
Customers under a signed DPA are notified of material subprocessor changes before they take effect.
Data locations
Workspace data is stored in the region configured for your account at provisioning. We confirm the exact region in writing before contract signature.
AvailableRegion selection is handled per enterprise agreement rather than self-serve. Confirm the region with sales before signing — do not assume a region is available.
Contact usPrompts sent to third-party AI engines are processed in the regions those providers operate. We cannot offer a commitment for in-region processing for external engines.
Contact usRetention
Monitoring data is retained for as long as your workspace is active, because historical runs are what make trend analysis possible. Retention windows for specific data classes, including shorter windows for regulated customers, are agreed in the contract.
Active workspaces
Prompts, runs, captured answers and reports are retained while the subscription is active so historical comparisons remain valid.
Deletion on request
Workspace owners can request deletion of their workspace data. We action verified deletion requests and confirm completion in writing.
Backups
Encrypted backups are held by the managed database platform on a rolling window; deleted records age out with that cycle.
Legal holds
We retain records where required by law or to resolve a dispute, and only for as long as that requirement lasts.
Privacy
The personal data we process is limited to workspace account data — names, work email addresses, role assignments and usage events. Monitoring prompts are business questions about brands and categories, not personal data, and customers are asked not to include personal data in them. Product analytics run behind a consent gate. Full detail is in the Privacy Policy and the privacy documentation.
Data subject requests
Access, correction, export and erasure requests can be sent to privacy@citerank.in. We acknowledge requests and respond within the statutory period applicable to the requester.
Data Processing Addendum
CiteRank acts as processor for customer workspace data and offers a standard Data Processing Addendum covering processing scope, subprocessor notification, security measures, international transfer mechanisms and assistance with data subject requests.
Vulnerability disclosure
We welcome reports from security researchers. Send findings to security@citerank.in with reproduction steps and the affected URL. Please give us reasonable time to remediate before public disclosure, do not access or modify other customers' data, and do not run denial-of-service or high-volume automated testing against production.
Acknowledgement
We acknowledge valid reports within 3 business days.
Triage
We confirm severity and expected remediation timeline after reproduction.
Safe harbour
Good-faith research within these rules will not trigger legal action from us.
We do not currently operate a paid bug bounty programme.
Incident management
Suspected security incidents are triaged by the engineering team on receipt. Our process is detect and contain, assess scope and affected workspaces, remediate, then notify. Where a personal data breach affecting customer data is confirmed, we notify affected customers without undue delay and within the timelines set out in the DPA.
Operational availability is published on the status page, which is maintained manually and is not an automated telemetry feed. Customer-impacting incidents are communicated directly to affected workspaces by email.
Certification status
SOC 2 Type II audit in progress
SOC 2 Type II audit in progress. We follow SOC 2 aligned controls across our organisation and infrastructure. Reports are available during Enterprise security review.
GDPR & DPDP alignment
We operate under a DPA aligned to the EU GDPR and India's Digital Personal Data Protection Act. Alignment is a contractual and operational commitment.
ISO/IEC 27001
Alignment with ISO 27001 standards is on the compliance roadmap after SOC 2.
Penetration testing
Independent penetration-testing evidence is available during Enterprise security review where applicable. Contact security for the latest assessment status.
Business continuity
Backups
Application data is backed up automatically by the managed database platform, with encrypted point-in-time recovery within the provider's retention window.
Recovery
Infrastructure is reproducible from version-controlled configuration, so the application layer can be redeployed without manual rebuild.
Recovery objectives
Formal RTO and RPO commitments are agreed per enterprise contract rather than published as a blanket commitment.
Provider dependency
Continuity depends on our cloud and AI engine providers. An outage at an engine provider pauses affected monitoring runs; they resume when the provider recovers.
AI provider data handling
Monitoring works by sending prompts to third-party AI engines and capturing what they return. This is the part of the service most often reviewed in security assessments.
- What we send: the monitoring prompt text you configure — category and brand questions such as "best enterprise AI visibility platforms". We do not send your customer records, uploaded documents or workspace credentials to AI engines.
- What we receive and store: the engine's answer text, cited sources and run metadata, so results can be compared over time.
- Where it is processed: inside each provider's own infrastructure, under that provider's terms. We use business/API tiers where available rather than consumer endpoints.
- Training: we do not authorise our providers to use customer prompt content to train foundation models where the provider's API terms allow opt-out.
- What we cannot control: an external AI engine's own retention, logging and abuse-monitoring behaviour. If your assessment requires provider-level commitments, request our current provider terms summary.
Enterprise Security Review
Security Documentation
Request Security Pack
For enterprise procurement, we provide a complete security review pack including our latest independent assessments, network architecture diagrams, and internal security policies.
Request Security DocumentationNote: Independent penetration-testing evidence and SOC 2 status updates are available during Enterprise security review where applicable. Contact security for the latest assessment status.
Have a security question?
Our team completes vendor questionnaires, security assessments and procurement reviews. If a control you need is not listed above, assume it is not in place and ask us.
