Security
Security
Last updated: 2026-08-12
We check public websites and optionally ask AI engines about a brand. This page states what that means for security — without fake compliance badges.
What we fetch
- Public HTTP(S) pages and sitemaps you ask us to check.
- AI-engine APIs (via our providers) when you unlock the full check — with spend caps and a kill switch.
- We do not ask you for CMS passwords, SSH keys, or DNS control to run a free grade.
Secrets & infrastructure
- Logged-in workspace auth uses Clerk — not a fake SSO badge strip.
- The app runs on Vercel; product data lives in Supabase — where we host and store, not a rented badge.
- Provider API keys live in server environment variables — not in the browser bundle.
- Lead emails and grade snapshots are stored for product operation (see Privacy).
- Cost controls (`canSpend` / kill switch) exist so a bug or abuse spike cannot run unbounded paid probes.
What we won’t claim
We won’t paste SOC2 / ISO / HIPAA / SSO logos we haven’t earned. When formal attestations exist, they’ll be linked here with dates. Until then: least privilege, no client secrets for free checks, and honest disclosure of what we measure.
Report a concern
Use Talk to us. Include the URL you checked and what looked wrong — we treat security reports as priority over marketing asks.