Legal
Security
Last updated July 28, 2026
AutoRank AI is built to handle CMS credentials and publishing workflows carefully. This page summarizes our current security posture.
1. Application security
Accounts use hashed passwords and optional email one-time codes for verification. Sessions are managed by Convex Auth over HTTPS.
2. Credential handling
CMS secrets and OAuth tokens are encrypted before persistence using an application encryption key. Production callbacks use your configured SITE_URL / Convex HTTP endpoints rather than localhost.
3. Infrastructure
The web app is hosted on Vercel. Backend data and jobs run on Convex. Access to production admin tools is limited to allowlisted operators.
4. Your responsibilities
Use strong unique passwords, keep CMS admin accounts protected, and grant AutoRank only the scopes it needs. Rotate credentials if a team member leaves or a token may have leaked.
5. Reporting issues
If you believe you found a vulnerability, email hello@autorankseoai.com with details and avoid public disclosure until we can investigate.
Questions about this policy? Email hello@autorankseoai.com or return to the homepage.