Security

Security & data practices

An honest description of how RankedByAI is built and how your data is handled — no compliance theater, just what we actually do.

Infrastructure: Cloudflare edge

RankedByAI runs entirely on Cloudflare's serverless platform — Workers for compute, D1 for the database and KV for report storage. There are no servers of our own to patch, and every request is served over TLS from Cloudflare's global edge network.

This also means we inherit Cloudflare's platform security: DDoS protection, network-level encryption between data centers, and SOC 2-audited data center operations. We are a small product and we deliberately build on infrastructure with a stronger security track record than anything we could operate ourselves.

What we store, and where

Scan reports (the business name, website, industry, city and the AI answers we sampled) are stored in Cloudflare KV and D1. Data in both services is encrypted at rest by Cloudflare.

For monitoring customers we additionally store the email address you sign up with, your dashboard access token, and the weekly scan history for your business. We do not store passwords — dashboards use unguessable token links instead of accounts.

Payment details never touch our systems: checkout and billing are handled by Paddle, our merchant of record. We only receive a transaction reference and subscription status via signed webhooks.

Access control

Customer dashboards are protected by long random tokens; only someone with your private link can view your data. Administrative endpoints require separate secret keys, are rate-limited, and are never exposed in client code.

Internal access to production data is limited to the operators of the service and used only for support and debugging.

GDPR position

Scans query public-facing AI models about businesses — the same questions anyone could ask. Reports contain business information, not consumer profiles. The personal data we process is limited to the email address of monitoring customers and standard technical logs.

You can request deletion of your scan reports, dashboard and email at any time by writing to support@zalize.com; we honor deletion requests within 30 days. We do not sell data, run third-party advertising trackers, or share your email with anyone.

Data retention

Free scan reports expire automatically one year after creation (KV time-to-live). Funnel metrics are aggregate counters with no personal data. Monitoring history is kept for as long as your subscription is active, and deleted on request.

Reporting a vulnerability

If you believe you have found a security issue, email support@zalize.com with the details. We read every report and will respond as quickly as we can. Please avoid accessing data that is not yours while testing.

Last updated: August 2026. Questions? Email support@zalize.com. See also our privacy policy.

Check your AI visibility — no signup needed

Free scan