Product

Security

Last updated

Rankomodo handles access to Google Search Console, Google Analytics, Bing and WordPress. These are the controls the service is built with; they apply to every account. To report a vulnerability, write to security@rankomodo.com.

Access

  • Google and Bing connections are read-only. Access tokens are encrypted at rest and deleted when you disconnect.
  • Each account’s data is separated at the database level, so one customer’s queries cannot read another customer’s rows.
  • Inside an account, owners, members and viewers have different rights per project. Approvers are a separate grant that can be revoked at once.

Changes to WordPress

  • The connector plugin signs every request with a key unique to each site and accepts only the operations Rankomodo needs.
  • Nothing is written without an approved change set. Each approved change waits 10 seconds so it can be cancelled.
  • Every change stores the previous value, so it can be rolled back. Content inside page builders is never edited.

Infrastructure

  • All traffic to rankomodo.com is served over HTTPS through Cloudflare.
  • The application server accepts no direct connections from the internet; traffic reaches it through an encrypted Cloudflare Tunnel.
  • The public website loads no third-party scripts, trackers or fonts.
  • Card data never reaches our servers; Paddle and Pakasir handle payment details.

Reporting a vulnerability

Email security@rankomodo.com with the steps to reproduce. Please do not access other customers’ data, run denial-of-service tests, or test against accounts you do not own. We will confirm receipt within 3 working days and keep you updated until it is fixed. We do not run a paid bug bounty yet.