Plain facts about your data.
Your prompts, answers and crawls say a lot about your business. This is what we do to protect them today — and what we don’t do.
What’s in place.
Scoped to your account
Every query is checked against the signed-in account, and projects, answers and audits are looked up by owner — a guessed id returns nothing.
Passwords and sessions
Passwords are hashed with scrypt. Sessions use httpOnly, same-site cookies and are stored hashed. Sign-in, reset and form endpoints are rate-limited, and reset and confirmation links are single-use.
Encryption in transit and at rest
The site is served over HTTPS. Our hosting and database providers encrypt data in transit and at rest; we do not run our own data centres.
Careful crawling
Anything that fetches a URL you give us refuses private and internal addresses, re-checks every redirect, and caps time and size. Multi-page audits need you to prove you control the domain.
Payments handled by Stripe
Card details go to Stripe, not to us. We store a customer id and your subscription status.
Human in the loop
Citeroot writes drafts and reports. Publishing, outreach and changes to your site stay with you.
Your data is yours.
- We do not use your data to train models. To collect answers we send your prompts and brand names to the AI providers on the subprocessors page; each provider’s API terms govern what it does with them.
- Export everything from Settings as JSON, answers as CSV on paid plans, or delete a project or your whole account at any time.
- Our crawler identifies itself as CiterootBot and honours robots.txt — see /bot.
- The database region is whichever region the operator chose when deploying; there is no per-customer region choice.
Compliance status
We hold no SOC 2, ISO 27001 or similar certification, we have not had an independent penetration test, and we do not claim either. There is no audit log, SSO or role-based access yet. If your procurement needs those, tell us before you buy.
Found a vulnerability?
Email security@citeroot.app with the details and steps to reproduce. We aim to acknowledge reports within two business days and to keep you updated until it’s resolved.
- Please give us reasonable time to fix an issue before disclosing it publicly.
- Don’t access data that isn’t yours, degrade the service or run automated scans against production at volume.
- We won’t pursue legal action against good-faith research that follows these guidelines.
Our machine-readable contact is at /.well-known/security.txt.
Questions for our security team?
We’ll answer plainly — including where the answer is “not yet”.