Privacy Notice
Last updated: August 2026.
What we collect
Account details (your email and organization), scan inputs (the domains you submit and proof of ownership), the findings and evidence we generate for you, and billing metadata handled by our payment processor. We collect the minimum needed to run an audit and bill for it.
Evidence & secrets
Reports can surface sensitive material, for example a leaked credential found on your own site. We mask secret values in the evidence we display and hold the unredacted copy in an encrypted store scoped to your account. We never sell your data.
How we use it
To run scans, deliver and store your reports, send the alerts you enable, provide support, and operate billing. Payment card details are processed by Stripe and never stored on our servers.
Sub-processors
We rely on a small set of vendors to operate: Supabase (database, authentication, and encrypted storage for reports and evidence), Stripe (payments, card data never touches our servers), and an LLM provider (the audit operator model; it receives redacted scan context, and secret values are masked before they reach it). We keep an up-to-date list and will give notice of material changes. A Data Processing Agreement (DPA) is available on request for business customers, contact us.
Retention & deletion
Reports and baselines are retained while your account is active so monitoring can diff against them. You can request export or deletion of your data at any time; we remove it within a reasonable window except where we’re required to retain records for legal or billing reasons.
Your choices
You control which domains are scanned and which notifications you receive. To exercise any data right, or to ask how a specific piece of information is handled, contact us.
This notice sits alongside our Terms of Service.