Security
RankEasy is designed around scoped access, revocable credentials, connector-level permissions, and reviewable publishing workflows.
Access model
RankEasy prefers OAuth, API tokens, WordPress Application Passwords, Shopify app authorization, and connector-specific credentials over server-level access.
SSH policy
SSH is not the default integration path and should not be retained for normal publishing. It is used for managed installation, migration, or support when a customer explicitly approves it.
Connector safety
- HMAC-signed push mode for public connector endpoints
- Pull mode for private or panel-managed servers
- No remote raw database writes for legacy CMS systems
- Revocable credentials and publish logs
Editorial control
Teams can use drafts, approvals, scheduled publishing, refresh states, and rollback records before and after content goes live.