SECURITY WHITEPAPER & SOC 2 SUMMARY
Last Updated: June 18, 2026. Effective immediately.
SECURITY WHITEPAPER & SOC 2 COMPLIANCE SUMMARY
Last Updated: June 18, 2026. Effective immediately.
1. Security Architecture Overview
At SageRank, the confidentiality, integrity, and availability of client data is paramount. The platform is operated by SageRank Software Solutions FZ-LLC (Ras Al Khaimah, UAE) and is engineered in alignment with SOC 2 Trust Services Criteria.
2. Infrastructure & Cloud Compliance
SageRank is deployed on enterprise cloud infrastructure hosted by Amazon Web Services (AWS) and Cloudflare. Our infrastructure partners maintain independent third-party certifications including:
- SOC 2 Type II: Evaluated under AICPA Trust Services Criteria for Security, Availability, and Confidentiality.
- ISO/IEC 27001:2022: Certified Information Security Management Systems.
- PCI-DSS Level 1: Audited payment gateway environments through Stripe and Paddle.
3. Cryptographic Standards & Data Protection
- Encryption in Transit: TLS 1.2 and TLS 1.3 enforced across all API, dashboard, and WebSocket endpoints with strict HSTS headers.
- Encryption at Rest: AES-256 encryption across all persistent PostgreSQL databases and diagnostic caching volumes.
- Key Management: Automated key rotation managed through cloud Key Management Services (KMS).
4. Access Control & Zero Trust
Internal access to production environments is governed by Zero Trust principles, requiring Multi-Factor Authentication (MFA), least-privilege role-based access control (RBAC), and encrypted bastion VPN tunneling.
5. Mandatory Domain Ownership Barrier
To prevent unauthorized reconnaissance, active security matrix tools require cryptographic domain verification via DNS TXT records (sagerank-verification=TOKEN). Unverified domains cannot be probed.
6. Security Inquiries
For vulnerability disclosures, SOC 2 documentation inquiries, or security whitepaper details, please contact legal@sagerank.io.