Security
Last updated Sep 1, 2026
Application security
Passwords are hashed with bcrypt. Sessions use HTTP-only, SameSite cookies. Cross-site requests to state-changing endpoints are blocked. All inputs are validated server-side, and authorization is enforced on every request with strict tenant isolation.
Encryption
Data is encrypted in transit with TLS. OAuth tokens and two-factor secrets are encrypted at rest with AES-256-GCM. API keys are stored as SHA-256 hashes and shown only once.
Account protection
Two-factor authentication with recovery codes, session management, rate limiting on authentication and audit logs for workspace activity.
Outbound requests
Website audits and sitemap fetching block private network addresses to prevent server-side request forgery.
Reporting a vulnerability
Email security@rankspire.tech. We acknowledge reports within two business days and do not pursue good-faith research.