Privacy Policy
Last updated Sep 7, 2026
The short version
We collect as little as we can get away with. We do not sell data, we do not run third-party advertising or analytics scripts, and we do not set tracking cookies. The only cookies we set are the ones required to keep you logged in and to protect forms from cross-site request forgery.
The scan data we hold is about domains — DNS records, certificates, HTTP headers — not about people.
What we collect, and why
- Account information — your email address, an optional name, and a hashed password. Needed to give you an account and to contact you about the service.
- Organisation information — your workspace name, branding you upload, and the client names and domains you enter. This is your data; we process it to provide the product.
- Scan results — publicly observable configuration of the domains you scan: DNS records, certificate details, HTTP response headers, and the homepage HTML we parsed. Retained so we can show you what changed over time.
- Billing information — handled entirely by Stripe. We store your Stripe customer identifier and your subscription status. We never see or store card numbers.
- Usage events — which features you used and when, so we can tell whether the product is working. Tied to your account.
- Traffic analytics — page path, referring domain, and UTM parameters. Visitor counting uses a salted hash of the IP address that rotates every 24 hours, so it cannot be reversed or used to follow anyone between days.
- Security logs — IP address and user agent on login sessions and audit events, kept so you can see who did what in your workspace and so we can investigate abuse.
What we do not collect
- We do not use third-party analytics, advertising, session-recording, or heat-mapping tools.
- We do not set cookies for any purpose other than authentication and CSRF protection.
- We do not store raw IP addresses for marketing analytics — only a daily-rotating salted hash.
- We never handle payment card details. Those go directly to Stripe.
- We do not read, receive, or process your clients’ email content.
Where your data is stored
Application data is stored in a PostgreSQL database hosted in the United States. Backups are encrypted and retained for 30 days. All traffic to and from the service is encrypted with TLS.
Sub-processors we rely on: Stripe (payments), Twilio SendGrid (transactional email), Anthropic (AI-generated report narrative and support drafting), and our hosting and database provider. We will keep a current list of sub-processors on this page.
AI processing
We use a large language model to write the plain-English narrative in reports and to draft support replies. What is sent to the model is the finding data from a scan (check names, statuses, severities, domain name) or the text of your support message. Security scores are never produced by a model — they are calculated by a fixed ruleset.
We do not send your password, billing details, or your client contact details to any AI provider. Our AI provider does not train models on data submitted through their business API.
Retention
- Scan results — retained for 24 months, so year-over-year comparisons work. Deleting a domain deletes its scan history immediately.
- Anonymous public scans (run without an account) — retained for 30 days, then deleted.
- Traffic analytics — retained for 14 months.
- Audit and security logs — retained for 12 months.
- Closed accounts — all workspace data is deleted within 30 days of account deletion. Records we are required to keep for tax and accounting purposes (invoices) are retained for 7 years.
Your rights
You can export your data at any time from your workspace settings, and you can delete your account from the same place. Deleting your account removes your workspaces, clients, domains, scans, and reports.
If you are in the UK, EU, or a jurisdiction with equivalent rights, you may request access to, correction of, or deletion of your personal data, and you may object to processing. Please use our contact form and we will respond within 30 days.
Scanning other people’s domains
Our free scan accepts any domain, and it deliberately only performs checks equivalent to visiting a website: DNS lookups, one TLS handshake, and requests to the site’s own published pages. We do not port-scan, we do not attempt authentication, and we do not attempt to exploit anything.
If you operate a domain and would like it excluded from scanning, use our contact form from an address at that domain, or naming it, and we will verify control and add it to our permanent denylist.
Contact
Privacy questions: our contact form. Everything else: our contact form.