DRAFT — attorney review required before publishing. This page has not been reviewed by a lawyer. Statements marked [ATTORNEY] need confirmation before the page goes live.
Security at ClinicRankPro, Georgetown, TX
ClinicRankPro protects client accounts with least-privilege access, a password manager, two-factor authentication on every account, and removal within five business days of an engagement ending. Our website sits behind a web application firewall with automatic updates and off-site backups. Reports and data are encrypted in transit and at rest. If something goes wrong, we tell you.
Reviewed by [OWNER NAME], last reviewed 16 September 2026. This page describes our working practices. It is not a certification or a guarantee.
How do we control access to client accounts?
- Least privilege. We work as a manager on Google Business Profile, an editor or administrator on the website, and a viewer or editor on Analytics, Search Console and Ads. You stay the owner of every account, always.
- No shared passwords. We never ask for your password and never share ours. Each person has their own login on every system.
- Password manager. Every credential lives in a password manager with a unique, generated password. Nothing is stored in email, chat, spreadsheets or browser autofill.
- Two-factor authentication everywhere. On the password manager, email, Google, hosting, domain registrar, the website admin, and every tool that supports it. Hardware or app-based codes, not SMS, where the service allows.
- Offboarding. When an engagement ends we remove our own access from every account within five business days and confirm by email with the list. Contractors, if any, lose access the day their work ends.
- Access log. Each client file records which accounts we hold access to and at what level, so a handover or an audit is a matter of reading one list.
How is the website hardened?
The same baseline we apply to every client site we host, because healthcare sites are targets.
- Cloudflare in front of the site: DNS, CDN, web application firewall, bot rules and TLS certificates
- Automatic minor-version updates for WordPress, plugins and themes reviewed weekly, major versions tested first
- Off-site backups at least weekly, kept for 30 days, restore tested quarterly
- Login attempt limits, a non-obvious administrator username, and two-factor login on the admin
- Minimum plugins, each from a maintained source, removed when no longer needed
- Forms with honeypot spam protection and no file uploads, and the form webhook authenticated with a key
Where is data stored, and how is it encrypted?
In three places, each with a clear purpose. Form submissions live on the website host, which encrypts data at rest. Reports, audit data and each client’s configuration live on a machine we control, with full-disk encryption and scheduled backups. Client accounts stay in your own systems; we hold access, not copies. Every connection between these places, and between us and you, uses encrypted transport. Report PDFs are emailed to the address you gave us and nowhere else. Retention periods are in the Privacy Policy.
How is email secured?
Our sending domain publishes SPF, DKIM and DMARC records so that mail claiming to come from us can be checked and forged mail rejected. [DMARC policy: quarantine or reject, confirm current record.] Our mailbox has two-factor authentication and phishing-resistant sign-in. We never send credentials, one-time codes or account recovery details by email, and we will never ask you to.
Who are the sub-processors?
The hosting, email, CRM, search data, Google, AI model and payment providers listed in the Privacy Policy. Each one has its own security program, and we choose providers that publish one. AI models run behind a private gateway we host; see the AI Use Policy.
What happens in a security incident?
- Detect. Uptime monitoring, Cloudflare alerts, host malware scanning, and login alerts on every account. A hacked or down client site is treated as an incident.
- Contain. Rotate affected passwords and keys, revoke sessions, restore from a clean backup where needed, and block the route in.
- Notify. Affected clients are told within [N] business days of discovery, with what happened, what was affected, and what we did. A client site outage or hack is reported within the hour. [ATTORNEY] Align the notification window with Texas breach notification law and any BAA in force.
- Post-mortem. A written account of cause, impact and fixes goes to affected clients, and the fix goes into the baseline for every site.
How do you report a vulnerability?
Email [EMAIL] with “Security” in the subject line and enough detail to reproduce the problem. We acknowledge within two business days, keep you informed, and credit you if you want. Please do not access, alter or download data beyond what is needed to show the issue, and do not test against client sites. We will not pursue anyone who reports in good faith within those limits. [ATTORNEY] Confirm the wording of this safe-harbor statement.
What do we ask of clients?
- Turn on two-factor authentication for the Google account that owns your Business Profile, and for your website admin
- Never email us a password. Add us as a manager or editor on the account instead; we send instructions
- Keep ownership of every account in the practice’s name, not an employee’s or a former vendor’s
- Tell us the same day if a staff member with account access leaves
- Never send patient information through any channel; see the HIPAA Statement
How do you contact us?
Email [EMAIL], write to [LEGAL ENTITY NAME], [BUSINESS ADDRESS], Georgetown, Texas, or use the contact page. Related pages: Privacy Policy, Terms and Conditions, California Privacy Notice, how we handle compliance.
Frequently asked questions
What access do you need to my accounts?
Manager-level access, never ownership. You add us as a manager on Google Business Profile, an editor or administrator on the website, and a viewer or editor on Analytics and Search Console. You can see everything we do and remove us in one click. We never ask for your password.
How quickly is your access removed when we stop working together?
Within five business days of the end date, and we confirm by email with a list of every account we were removed from. If you would rather remove us yourself on the last day, that is fine too.
Where are my reports and data stored?
Reports, audit data and client configuration live on a machine we control, backed up on a schedule, plus the website host for anything submitted through the site. Client accounts stay in your systems; we hold access, not copies. The host encrypts data at rest, and every connection uses encrypted transport.
What happens if you get breached?
We contain it first, then tell every affected client within [N] business days of discovery, with what happened, what was affected, and what we did. Passwords are rotated, access is reviewed, and a written post-mortem goes to affected clients.
How do I report a security problem?
Email [EMAIL] with “Security” in the subject line. We acknowledge within two business days and keep you informed. We will not take action against anyone who reports in good faith and does not access or alter data beyond what is needed to show the problem.
Do you use a password manager?
Yes, for every credential, with a unique password per account and two-factor authentication on the manager itself. No password is shared by email, chat or document, and no account is shared between people.