Security

Security

Last updated: 2026-08-12

We check public websites and optionally ask AI engines about a brand. This page states what that means for security — without fake compliance badges.

What we fetch

  • Public HTTP(S) pages and sitemaps you ask us to check.
  • AI-engine APIs (via our providers) when you unlock the full check — with spend caps and a kill switch.
  • We do not ask you for CMS passwords, SSH keys, or DNS control to run a free grade.

Secrets & infrastructure

  • Logged-in workspace auth uses Clerk — not a fake SSO badge strip.
  • The app runs on Vercel; product data lives in Supabase — where we host and store, not a rented badge.
  • Provider API keys live in server environment variables — not in the browser bundle.
  • Lead emails and grade snapshots are stored for product operation (see Privacy).
  • Cost controls (`canSpend` / kill switch) exist so a bug or abuse spike cannot run unbounded paid probes.

What we won’t claim

We won’t paste SOC2 / ISO / HIPAA / SSO logos we haven’t earned. When formal attestations exist, they’ll be linked here with dates. Until then: least privilege, no client secrets for free checks, and honest disclosure of what we measure.

Report a concern

Use Talk to us. Include the URL you checked and what looked wrong — we treat security reports as priority over marketing asks.

Common questions

Still stuck? Talk to us
Want the report card first?Paste your site. Free check. No signup. Talk to us when the gap list needs a human.
Free check

Not claimed here. We won’t paste attestations we haven’t earned. When formal reports exist, they’ll be linked with dates — not a marketing badge strip.