Security built into every layer
AmpliRank is engineered from the ground up for B2B enterprises that require verifiable data isolation, cryptographic evidence auditability, and zero-training guarantees.
Zero Model Training on Customer Data
We access AI models strictly via enterprise API agreements with OpenAI, Anthropic, Google, and Perplexity. Under these commercial terms, customer queries and brand data are never used to train foundation models.
Isolated Multi-Tenant Architecture
Every brand, competitor matrix, prompt panel, and captured answer is scoped by workspace ID. Foreign key boundaries and tenant-scoped transactions strictly prevent cross-workspace data leakage.
Cryptographic Provenance & CAS Fingerprints
Published recommendations and briefs use compare-and-set (CAS) cryptographic fingerprints. If underlying citations or evidence change between review and publication, the state transition is rejected until re-reviewed.
Enterprise Encryption in Transit & at Rest
All web traffic terminates over TLS 1.3 on Cloudflare's global edge network. Primary databases (Neon PostgreSQL) enforce TLS connections with AES-256 encryption at rest.
Hashed Credentials & Scoped REST Tokens
User passwords utilize bcrypt with UTF-8 byte boundary defense. REST API keys are generated with secure cryptorandom tokens and stored strictly as SHA-256 hashes.
HMAC-SHA256 Webhook Verification
Outbound alert webhooks include timestamped HMAC signatures in the request header, enabling receivers to verify delivery authenticity and defend against replay attacks.
Vulnerability Reporting & Compliance Inquiries
We welcome coordinated vulnerability disclosures and compliance audits from enterprise security teams. If you discover a potential vulnerability or need a completed vendor assessment questionnaire, please contact our security team directly.