Enterprise Ready

Security & Trust.
Enterprise-Grade Controls.

FixRank is engineered with a security-first architecture. We protect your GSC access credentials, staging code, and metadata with SOC-2 aligned protocols.

Search security parameters
Table of Contents
Core Diagnostics

Secure Vault Diagnostics

Execute an automated security and encryption check on this browser session.

LAST MODIFIED: FEBRUARY 2026SECURITY LEVEL: CLASS-A
1

Security Governance & Program

Our Information Security Program is designed to protect the confidentiality, integrity, and availability of customer data. Controls are aligned with SOC 2 Trust Services Criteria and GDPR requirements. FixRank does not currently claim ISO 27001 or SOC 2 certification, but our architecture supports future certification readiness, maintained by continuous technical reviews.

PROTOCOL: Security processes are audited quarterly by specialized third-party penetration testing groups.
2

Compliance & Regulatory Alignment

FixRank complies with EU GDPR, UK GDPR, UK Data Protection Act 2018, Standard Contractual Clauses (SCCs), and the UK International Data Transfer Addendum. FixRank acts as Data Controller for account/billing data and Data Processor for customer website engagement data, providing secure DPAs.

3

Infrastructure & Cloud Security

Our enterprise-grade cloud infrastructure is hosted primarily in UK/EU regions across highly secured AWS/Cloudflare clusters. We maintain a high-availability architecture, strict VPC environment isolation, secure network configurations, DDoS mitigation, and robust Web Application Firewall (WAF) protection at the Edge.

VPC networks with strict ingress/egress firewalls.
Edge routing utilizing Cloudflare Magic Transit DDoS shields.
Multi-region backup nodes with hot failovers.
4

Data Protection & Encryption

We enforce cryptographic safeguards across all layers of the platform. Database backups are continuously encrypted, and keys undergo automated rotation schedules.

TLS 1.2+ (with TLS 1.3 preferred) encryption for all data in transit.
AES-256 encryption at rest for customer databases and disk volumes.
HMAC-SHA256 signatures verifying API requests and sandbox changes.
5

Identity & Access Management

We enforce strict identity verification to shield administrative systems. Multi-Factor Authentication (MFA) is mandatory for all core developers and sysadmins accessing production clusters.

Role-Based Access Control (RBAC) separating staging and production.
Least-privilege operational guidelines for support staff.
Comprehensive immutable audit logging of administrator sessions.
6

Secure Development Lifecycle (SDLC)

Security is deeply integrated into our software pipeline. Code updates are fully audited inside isolated local repositories prior to merge execution, maintaining absolute runtime reliability.

Mandatory dual-engineer review for all production code adjustments.
Automated dependency vulnerability scanners (Snyk/GitHub Dependabot).
Isolated sandboxed environments validating staging rollbacks.
7

Monitoring & Threat Detection

We operate a round-the-clock telemetry model. Auditing structures monitor network activities, detecting and escalating anomaly events directly to our on-call engineers.

Real-time event logging via Datadog and AWS CloudWatch.
Anomaly detection models flagging malicious access payloads.
Automated IP ban limits on rapid, unauthorized crawling attempts.
8

Incident Response Framework

Our documented Incident Response Program ensures rapid detection, containment, investigation, and remediation of security incidents. In the event of a verified breach, we will notify affected customers without undue delay and report to regulators as mandated.

9

Business Continuity & Resilience

FixRank is built for resilience. We execute encrypted backups daily and validate recovery processes weekly to ensure our recovery point objective (RPO) and recovery time objective (RTO) align with enterprise needs.

10

Vendor & Sub-Processor Management

We conduct thorough security due diligence prior to onboarding any third-party integrations or cloud infrastructure providers. Standard DPAs are maintained with all partners. A complete Sub-Processor list is available upon request.

11

Data Retention & Minimization

We adhere to strict data minimization. Account records are kept while the workspace remains active, billing history is retained per UK legal tax mandates, and all temporary diagnostic HTML caches are purged automatically on rolling schedules.

12

International Data Transfers

Transfers across global crawl clusters are legally protected using Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and additional transit encryption protocols.

13

Data Subject Rights

We support all rights under GDPR/CCPA. Customers can request complete data export, specific correction, or permanent erasure from our networks. Privacy inquiries are processed within statutory 30-day windows.

14

Enterprise Documentation Available

To assist partners during vendor assessments, our security desk provides the following documents upon direct request: Standard DPA, Sub-Processor List, Security Overview Summary, Incident Response Plan, and GDPR Compliance Statement.

15

Contact & Corporate Information

For legal compliance, DPA reviews, and security audit logs, please reach out to our team at 10x Galaxy Ltd.

Security Operations: security@fixrank.ai
Privacy Inquiries: privacy@fixrank.ai
Corporate Address: 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom
16

Our Absolute Commitment

FixRank never sells user metrics or page copy, enforces transit and storage encryption by default, operates with complete operational transparency, and continuously refines security gates to thwart crawling hazards.

Edge WAF Infrastructure

Distributed Cloudflare Magic Transit

FixRank deploys all dynamic sandbox execution gateways directly at the Edge. Incoming crawler diagnostics are checked, verified, and parsed under absolute container separation, shielding staging pipelines from malicious script injection.

100% ISOLATEDVPC Staging Gates
TLS 1.3 STANDARDHandshake Shields
[ Trust Operations ]

Enterprise Security FAQs

Learn how we isolate staging databases and protect workspace API tokens.

Does FixRank save my production Google search secrets in plain text?

No. FixRank uses envelope encryption. Google Console access tokens are encrypted with AES-256 using specialized regional key rings.

Are the staging metadata hotfixes secure against spoofing attacks?

Yes. Every staged repair generated is verified using cryptographically signed HMAC signatures, guaranteeing only matching repositories can trigger merges.

Is FixRank SOC-2 Type II certified?

While FixRank is not currently SOC-2 certified, our security controls, VPC isolated networks, and SDLC guidelines have been designed from day one to exceed SOC-2 Trust Criteria standards.

What is your vulnerability patch SLA?

Critical vulnerabilities in dependency packages are automatically flagged and patched via scheduled daily CI checks, maintaining 100% dependency health.