Security

The least access that can do the job

Handing an agency the keys is the part B2B buyers rightly worry about. Here is exactly what we need, what we refuse to take, and how it's handled.

What we need, and why

Google Search Console

Read-only (restricted user)

Query and page performance data drives the keyword-gap analysis. Reading it never changes anything on your property.

Your CMS

Lowest role that can publish

For WordPress that means an Author account or an application password scoped to posts — enough to publish and update articles, nothing more.

Social channels

Publishing only

To distribute published content on the channels included in your plan. No access to messages or account settings.

What we never need

  • Admin or owner access to your CMS or hosting
  • Billing or payment details
  • Hosting control panels or DNS
  • Your customers’ personal data

How credentials are handled

No shared passwords: we use OAuth or application passwords wherever the platform supports them, so access is scoped and individually revocable. Secrets are kept in encrypted storage with restricted file permissions — never in code, tickets or email. When you cancel, access is removed within 7 days of contract end.

We process SEO and site data only — search metrics, page content, publishing accounts. We do not touch your customers' personal data. Everything we do is covered by UK GDPR, and a data processing agreement is available on request.

Infrastructure is self-hosted on servers we control in the EU — Telepoint data centre, Sofia, Bulgaria — with audit logging on access to client systems.

A note on pedigree: rankloop was built by an engineer with an identity & access management background — least-privilege is a habit here, not a compliance checkbox.

Questions from your security team? We're happy to answer them directly: [email protected]