Skip to content

Security

Last updated Sep 1, 2026

Application security

Passwords are hashed with bcrypt. Sessions use HTTP-only, SameSite cookies. Cross-site requests to state-changing endpoints are blocked. All inputs are validated server-side, and authorization is enforced on every request with strict tenant isolation.

Encryption

Data is encrypted in transit with TLS. OAuth tokens and two-factor secrets are encrypted at rest with AES-256-GCM. API keys are stored as SHA-256 hashes and shown only once.

Account protection

Two-factor authentication with recovery codes, session management, rate limiting on authentication and audit logs for workspace activity.

Outbound requests

Website audits and sitemap fetching block private network addresses to prevent server-side request forgery.

Reporting a vulnerability

Email security@rankspire.tech. We acknowledge reports within two business days and do not pursue good-faith research.