Trust & Security

Built for regulated, public-sector and enterprise buyers.

GenAI Ranker measures how AI engines answer questions about you and generates machine-readable corrections you publish on your own domain. Your verified record and every measurement stay yours — with sovereign, in-region, private-tenant or air-gapped deployment for public bodies. We are the engine; the data is yours.

Ownership

Your data stays yours

We do not sell your data, and we never train third-party models on it. You own your verified record, your measurements and your generated corrections — end to end.

We are the engine, the data is yours

GenAI Ranker measures and drafts; it never takes ownership of your record. Export it any time; request deletion of your workspace and its data and we action it promptly.

No third-party model training

Queries reach model providers (Anthropic, OpenAI, Google) through their business APIs, which do not use API data to train their models. We send only the question and the entity context needed to score visibility.

Published on your domain

Corrections are machine-readable assets you publish on your own site. Nothing is ever posted for you and nothing leaves your control without your explicit approval.

Residency

Where your data lives

Measurement runs in-region by default. For public-sector and regulated buyers, the whole platform can be deployed inside your own boundary — choose the posture that matches your data-residency and jurisdiction requirements.

In-region managed

We run the platform for you with measurement and storage pinned to your region — the fastest path, with data kept in-country.

Private tenant

A dedicated, single-tenant instance isolated from all other customers — separate database and compute, provisioned for your organisation alone.

Sovereign

Deployed inside a government-approved cloud or a boundary you nominate, under your data-residency and jurisdiction requirements.

Air-gapped / self-hosted

Installed entirely within your own network with no outbound dependency you haven't approved. You own the infrastructure and every byte on it.

Deployment posture is scoped during procurement — we map to your security architecture rather than asking you to adopt ours.

Accountability

Access & auditability

Every change to your verified record and every scan is accountable — with releasability controls built for government and defence use.

Role-based access

Owner / admin / member roles per workspace, with least-privilege service roles for automation and read-only, revocable API keys.

Audit-grade trail

An append-only event log records every fact added, removed or scanned — with actor and timestamp — alongside a full history of measurement runs. Exactly the trail a security review or an audit needs.

Releasability controls

A fact can be marked restricted. It is still measured for accuracy, but is never included in a generated correction draft — the interface shows a lock instead of the text.

Transparency

How measurement works

No black box. You can see exactly what we asked, what each engine answered, and why we graded it the way we did.

  1. Ask the questions in your verified record

    You define the entity, the facts and the exact question put to each engine. We ask only those questions — nothing you didn't set.

  2. Capture answers verbatim

    Each AI engine's answer is recorded word-for-word, with the sources it cited — so the evidence is the engine's own output, not a summary.

  3. Grade against the record, diagnose from evidence

    Answers are graded against your verified facts. The diagnosis is computed from evidence — including whether the fact is present in your page's own server-rendered HTML — not guessed.

  4. Nothing is published without your approval

    We draft corrections for you to review. You decide what to publish, on your own domain. Restricted facts are withheld from every draft.

Application security

Secure by construction

Measured, verifiable controls — stated as what we actually do, not aspirational badges.

Encryption in transit & at rest

All traffic is served over TLS (HTTPS). Data is encrypted at rest by our database provider. Secrets and API keys are held as environment secrets, never committed to the codebase.

Tenant isolation (Postgres RLS)

Every workspace is isolated at the database layer with row-level security policies scoped to your organisation. A query can only ever return your own rows — enforced by Postgres, not just application code.

Least-privilege access

Role-based access within each workspace (owner / admin / member). Background jobs use a scoped service role; API keys are read-only and revocable at any time from Settings.

Audited infrastructure

The managed platform runs on SOC 2 Type II–certified providers (Supabase, Vercel). Our own SOC 2 / ISO 27001 attestations are on the roadmap; security and procurement reviews are supported today, with documentation on request.

Responsible AI

We don't invent facts

Corrections are grounded entirely in the record you verified — the model rewrites and formats, it never sources the truth.

Grounded in your record

Every generated correction is built only from facts you have verified. The AI phrases them clearly — it does not supply new claims of its own.

Restricted facts withheld

Anything you mark restricted is excluded from all generated output, so sensitive detail is measured internally but never drafted for publication.

Human-in-the-loop

Optional automation never changes your live site on its own — it is off by default, drafts for approval, and every action is capped and logged.

Compliance & procurement

We support your security and procurement review directly. A Data Processing Agreement (DPA), our current sub-processor list, and security documentation are available to buyers on request. We engage through empanelment, tender or a purchase order — no self-serve card charge for public bodies.

  • DPA & sub-processor list on request
  • Security questionnaires supported
  • Empanelment / tender / PO engagement
  • SOC 2 / ISO 27001 on the roadmap

Found a vulnerability? Email hi@genairanker.com. We appreciate good-faith reports and won't pursue researchers acting in good faith.

Reviewing us for a public-sector deployment?

Tell us your data-residency, releasability and procurement requirements — we'll map a sovereign, in-region, private-tenant or air-gapped deployment to them, discreetly.

GenAI Ranker is operated by Saraiya Innovations Private Limited. See our Privacy Policy & Terms.