Self-host for full control, or run on Cloud with published sub-processors and the same BYO-provider model.
Hosted routes use HTTPS, and provider credentials are encrypted before they are stored. API keys are stored as hashes, not raw bearer secrets.
Self-hosted deployments keep the app, database, rank history, sessions, provider credentials and audit logs in infrastructure you operate. Self-host runs with no sub-processors.
Bring your own SERP and analytics providers. Credentials stay scoped to your project, are encrypted at rest, and provider costs remain between you and the provider.
Owner, Admin, Editor and Viewer roles gate project access, and an Auditor role can read audit records. Sensitive account, team, provider, key, schedule and data changes write redacted append-only audit records.
Security reviews can map clear data boundaries: Cloud sub-processors are listed below, self-host has none, and teams can export data through CSV, JSON packages and the REST API.
Please report suspected vulnerabilities privately. We acknowledge security reports within 48 hours and credit reporters when appropriate.
| Sub-processor | Purpose | Scope |
|---|---|---|
| Application hosting, managed databases and transactional email (SES) | Infrastructure | |
| Workflow engine, background workers and cache infrastructure | Workers | |
| Transactional email delivery | ||
| Error and performance monitoring | Diagnostics | |
| Product analytics | PlannedAnalytics | |
| Subscription billing and payments | PlannedBilling |
Logos provided by Logo.dev