Rankomodo handles access to Google Search Console, Google Analytics, Bing and WordPress. These are the controls the service is built with; they apply to every account. To report a vulnerability, write to security@rankomodo.com.
Access
- Google and Bing connections are read-only. Access tokens are encrypted at rest and deleted when you disconnect.
- Each account’s data is separated at the database level, so one customer’s queries cannot read another customer’s rows.
- Inside an account, owners, members and viewers have different rights per project. Approvers are a separate grant that can be revoked at once.
Changes to WordPress
- The connector plugin signs every request with a key unique to each site and accepts only the operations Rankomodo needs.
- Nothing is written without an approved change set. Each approved change waits 10 seconds so it can be cancelled.
- Every change stores the previous value, so it can be rolled back. Content inside page builders is never edited.
Infrastructure
- All traffic to rankomodo.com is served over HTTPS through Cloudflare.
- The application server accepts no direct connections from the internet; traffic reaches it through an encrypted Cloudflare Tunnel.
- The public website loads no third-party scripts, trackers or fonts.
- Card data never reaches our servers; Paddle and Pakasir handle payment details.
Reporting a vulnerability
Email security@rankomodo.com with the steps to reproduce. Please do not access other customers’ data, run denial-of-service tests, or test against accounts you do not own. We will confirm receipt within 3 working days and keep you updated until it is fixed. We do not run a paid bug bounty yet.