Security, explained plainly.
This page describes how Citationly protects customer data: the architecture, the controls, and the practices. It is written for the security teams and procurement reviewers who will read it closely, so it favors facts over reassurance.
How we think about security
Citationly's AI brand monitoring holds data that customers consider competitively sensitive: how AI engines describe their brands, where their visibility is weak, and what their optimization plans target. That data may not be regulated the way health records are, but a competitor gaining access to it would be a genuine business harm.
Least access, always.
Employees and systems get the minimum access required to do their job, granted deliberately rather than by default, and nothing more.
Boring, proven choices.
We build on established, widely used infrastructure and well-understood security patterns rather than novel, unproven approaches.
Honesty over theater.
This page claims only what is true. Where a control is planned rather than implemented, we say which.
Where and how the platform runs
Citationly runs on established cloud infrastructure with data centers that maintain industry-standard physical and environmental controls. Production systems are isolated from development and testing environments. The platform is architected for tenant isolation: each customer's monitoring data, competitive sets, and reports are logically separated.
Application servers run on managed cloud hosting, and your organization's data lives in PostgreSQL on encrypted storage volumes, backed by automated, encrypted backups. The background workers that run scans and analysis operate separately from the web application tier, so heavy analysis work never has direct access to the systems serving your dashboard.
How data is protected in transit and at rest
All data moving between your browser and the platform is encrypted in transit using TLS 1.2 or higher. Data stored within the platform is encrypted at rest using AES-256. Encryption keys are managed through the infrastructure provider's key management service, not handled manually by application code.
How access to your account is verified
Citationly accounts are protected by standard credential security, including enforced password requirements, and sign-in can also be handled through Google-backed identity via Firebase Authentication. Multi-factor authentication is available and recommended for all accounts. For Enterprisecustomers, single sign-on through your existing identity provider allows your organization's own authentication policies to govern access.
Who can see what, inside your organization and ours
Within your workspace, role-based access control lets administrators define what each team member can view and change. Within Citationly, employee access to customer data is restricted to roles that require it, granted on a least-privilege basis, and logged.
How we approach AI in the platform
Citationly's business is observing AI systems, and we apply the same scrutiny to our own use of them. Your data is not training material. Analytical AI is bounded, operating on collected answer data under our methodology. Engine querying is honest: the platform queries public AI engines the way a user would.
Retention, deletion, and your control over data
Customer data belongs to the customer. Monitoring history is retained for the life of the account because historical baselines are central to the service's value, but account closure triggers deletion of customer data from production systems within 30 days, with backups clearing on their normal expiry cycle afterward. For details on what personal information we collect, see the Privacy Policy.
Where we stand on formal attestations
Our internal security controls are aligned to the SOC 2 Trust Services Criteria. A formal third-party audit is in progress. We will publish the report as soon as it is issued, and we do not claim certification before then. Security documentation, including questionnaire responses for procurement processes, is available to evaluating enterprises on request through the security contact below.
Ask us the hard questions
Security reviews are welcome here. Send your questionnaire, request our documentation, or put your security team in a room with ours, at security@citationly.io.
Ready to put us to the test?
Our security team can walk your procurement or InfoSec group through any part of this document.