Security
Read-only access to every source, encryption, workspace isolation, what is kept and for how long, and how to delete a workspace or an account.
RankDebug sits on top of some of the most sensitive data a website has: its search performance, its analytics, its edge traffic and its release history. This page explains how that data is accessed, protected, kept and deleted.
Read-only access to every source
Every connection asks for read access and nothing more. RankDebug never writes to your Search Console, Google Analytics, CDN, repository or site.
| Source | What RankDebug asks for |
|---|---|
| Search Console | The webmasters.readonly scope |
| Google Analytics | The analytics.readonly scope |
| Cloudflare | A token you create with Zone → Zone → Read and Zone → Analytics → Read on one zone |
| Bing Webmaster Tools | An API key you generate |
| GitHub | An app installation with read access to contents, deployments and metadata |
| GitLab | A token with the read_api scope only. A token with any write scope is refused |
From a connected repository, RankDebug reads each release's changes to find SEO-relevant edits and keeps only file paths and signal names, never a line of code. A deploy reported from CI carries only what you send, and the deploy endpoint is built for paths and signal names, not code.
The crawler only makes GET requests and never submits forms or logs in, except with a login or headers the site's owner gave it for their own site. RankDebugBot describes how it identifies itself and how to control it.
Disconnecting a source removes its credentials. You can also revoke RankDebug's access on the provider's side at any time.
Encryption
Traffic to the dashboard and the API is encrypted in transit, and webhooks are only sent to HTTPS endpoints.
Every credential you give RankDebug is encrypted at rest: connection tokens and keys, crawler logins and headers, webhook secrets and custom webhook headers. They are loaded only when they are used, never shown again after you save them, and kept out of logs, background job data and error reports. API keys and webhook secrets are shown once, when they are created.
Workspace isolation
Each workspace's data is kept apart from every other workspace's. Every request, whether from the dashboard, an API key or the agent, is checked against the workspaces the person behind it belongs to. A workspace or a resource you do not belong to answers exactly like one that does not exist.
API keys narrow this further. A key carries only the scopes it was given, and a key bound to one workspace cannot reach any other. Roles inside a workspace decide who can change things: a Viewer can read but not change anything, and crawler access, report sharing and workspace settings are for owners and admins. See Team, Roles and Workspaces.
The agent
The agent reads through the same checks as everything else, and only within your workspaces. Text it reads from web pages and other outside sources is treated as data, never as instructions. Actions that cost money or reach outside RankDebug, such as starting a crawl or resending a webhook, are proposed for your approval and do nothing until you approve them.
What is kept, and for how long
History is the point of RankDebug, so the data it pulls is kept. Search Console, Google Analytics, CDN and Bing history, crawl results, site checks and deploys stay in the workspace for as long as the workspace exists, including after a source is disconnected.
Some operational records are kept for a limited time:
| Record | Kept for |
|---|---|
| API request logs | 30 days |
| Webhook delivery attempts | 30 days |
| Workspace activity | 90 days |
| Security activity: members joining, leaving or changing role or access, and changes to two-step verification, passkeys, single sign-on and signed-in devices | Never pruned |
Deleting a workspace
The workspace owner can delete a workspace from Settings → Workspaces. Everything in it is deleted with it, and this cannot be undone.
Deleting your account
Delete Account, at the bottom of Settings, closes your account. Type your email address to confirm. If a workspace you own still has other members, remove them or delete that workspace first.
When you confirm, you are signed out everywhere right away and what you owe so far is billed. Your account and every workspace you own, with all their data, are permanently deleted after 30 days. This cannot be undone.
Reporting a security issue
If you find a security problem in RankDebug, tell us through the contact form.
Related documentation
- RankDebugBot
The crawler RankDebug uses to audit websites for their owners. How to recognise it, how it behaves, and how to allow or block it.
- Team, Roles and Workspaces
Invite your team, choose what each person can do, and decide which workspaces they see.
- Agent
Ask questions about your site in plain language. What the agent can read, what it can do, and how it handles text from the web.