Infrastructure & encryption
What RankNest runs on, and how your data is protected
SOC 2 Type II Infrastructure
RankNest runs on Supabase, which is SOC 2 Type II–compliant. We don't hold our own SOC 2 report.
GDPR-Aligned Practices
Data processing practices built around EU data protection principles
AES-256 Encryption
The same symmetric cipher used by US government TOP SECRET data, applied to every row at rest
CCPA-Aligned Practices
California Consumer Privacy Act principles applied to how your data is handled
How the platform is built
The controls that sit between an attacker and your data
Encryption at Rest and in Transit
All data encrypted with AES-256 at rest and TLS in transit, via Supabase's SOC 2 Type II–compliant infrastructure.
Multi-Factor Authentication
Optional MFA support via authenticator apps (TOTP). Adds an extra layer of protection beyond passwords.
Row-Level Security
Database-level access controls ensure complete data isolation between agencies. Your clients never see each other's data.
Revocable Google OAuth
Google Search Console and Google Business Profile access is granted through OAuth, which you can revoke from your Google account at any time. We never see your Google password.
Audit Logging
Key account and data-access events are logged with a timestamp so activity can be traced after the fact.
Automated Backups
Supabase runs continuous backups with point-in-time recovery on the underlying database.
Access Controls
Role-based permissions (Owner, Admin, Member) control who on your team can access sensitive features and data.
Data protection & privacy
What happens to your data, and what doesn't
What We Do
- Encrypt all data at rest with AES-256
- Use TLS for all data in transit
- Isolate data between agencies with row-level security
- Run on Supabase's SOC 2 Type II–compliant infrastructure
- Give you a plain-English answer if you ask how something works
- Allow you to export or delete your data anytime
- Notify you promptly if a data breach affects your account
- Use revocable Google OAuth for GSC and GBP access, never your password
What We Don't Do
- Sell your data to third parties
- Share your data with advertisers
- Use your data for purposes beyond providing RankNest
- Store credit card numbers (handled by Stripe)
- Access your Google Search Console data without permission
- Train AI models on your proprietary data
- Share data between different agency accounts
- Read your private messages or communications
- Track you outside of the RankNest platform
- Retain data longer than legally required after deletion
Infrastructure
RankNest is hosted on Supabase, which is SOC 2 Type II–compliant
Database
Row-level security policies enforce data isolation on every query, not just at the app layer
Backups
Point-in-time recovery on the underlying database
Encryption
Applied to every row at rest, in addition to TLS in transit
Google Access
Revocable from your Google account at any time. We never see your Google password
Security Best Practices for Users
Help us keep your data secure by following these guidelines
Use Strong Passwords
Create unique passwords with at least 12 characters, including uppercase, lowercase, numbers, and symbols.
Enable Multi-Factor Authentication
Add an extra layer of security with MFA using an authenticator app like Google Authenticator or Authy.
Don't Share Credentials
Never share your password or login credentials. Use team member invitations to grant access to colleagues.
Review Team Permissions
Regularly audit team members and their permission levels. Remove access for former employees immediately.
Keep Software Updated
Use the latest version of your browser and operating system so you have the latest security patches.
Be Wary of Phishing
We'll never ask for your password via email. Always verify the URL is ranknest.io before logging in.
Use Secure Networks
Avoid accessing RankNest on public WiFi. If necessary, use a VPN to encrypt your connection.
Report Suspicious Activity
If you notice unusual account activity, contact our security team immediately at security@ranknest.io
Responsible Disclosure Program
We welcome responsible disclosure of security vulnerabilities
If you discover a security vulnerability in RankNest, please report it to our security team at security@ranknest.io
Please include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact and severity assessment
- Your contact information for follow-up
We commit to:
- Respond to your report within 48 hours
- Keep you informed of our progress
- Credit you for the discovery (if desired)
- Not pursue legal action for good-faith research
Please do not: Publicly disclose the vulnerability before we've had a chance to address it, access or modify user data, or perform actions that could harm our users.
Questions About Security?
Ask us anything about how your data is handled. We'll give you a straight answer
Email: security@ranknest.io