Security and trust
We'd rather be checkable than impressive. Here's what's true about how we handle your data — including the things we don't have.
What we access
Your public pages. We crawl the URLs you add to a project, the same way a search engine crawler would, and we identify ourselves in the user agent.
Your analytics, only if you connect it. Read access to Google Search Console and Google Analytics 4 through one OAuth, and optionally Bing Webmaster Tools. Read-only — we don't write to your properties, and you can disconnect at any time.
Nothing else. We don't ask for CMS credentials, server access, or DNS control.
What we store
Crawl results, findings, screenshots captured during scans, and the analytics we've read for your projects. Retention follows your plan: 30 days on Free, unlimited on paid plans.
What we deliberately don't record: prompts, generated answers, raw queries and secrets are kept out of our internal cost and audit records. That's an architectural rule in the codebase rather than a policy statement — the metering layer records what an operation cost, never what it contained.
Tenancy and access control
Every record is scoped to an organization. Cross-organization access is prevented at the query layer and enforced by authorization policies on tenant-owned data, with tests that specifically assert one organization cannot reach another's records.
Within your organization, access is role-based. API access uses tokens with per-token abilities, so an integration gets exactly the scope it needs and nothing more. Single sign-on is available on Enterprise plans.
Where it runs
Dedicated servers in a European data centre, managed by our team, with data stored in PostgreSQL. All traffic is served over HTTPS, including the WebSocket connection used for live scan updates.
Certifications — what we do and don't hold
We are not SOC 2 certified, and we do not have an audit in progress. Earlier versions of this site said compliance was "in progress". That wasn't accurate, so we've removed it rather than repeat it. If SOC 2 is a requirement for your organization, we'd rather tell you now than in week six of a review.
Availability
We don't publish an uptime SLA. Earlier copy on this site claimed 99.9%; there is no SLA document behind that number. Enterprise agreements can include availability commitments — talk to us about what you need.
Reporting a vulnerability
If you've found something, get in touch and we'll respond. We won't pursue anyone acting in good faith.
Questions we haven't answered here
Data-processing agreements, sub-processors, encryption at rest, and how the AI providers we use handle retention are all reasonable things to ask about. We're not going to publish answers to them until they've been confirmed by the person accountable for them, so ask us directly and you'll get a specific answer rather than a paragraph of reassurance.
See also our privacy policy and cookie policy.