Security
How the service is built, what reaches your site when we analyse it, and what we keep afterwards.
What reaches your site
Analysing a page means fetching it, so the first question is what we send and what we are prevented from reaching.
A request identifies itself as our crawler and follows your robots.txt. A site crawl fetches one page at a time with a gap between requests, and honours a Crawl-delay if you set one. We stay on the host you gave us: links to other sites are recorded and checked for whether they resolve, never crawled.
We do not submit forms, sign in, or send anything other than GET requests. Nothing we do changes your site.
A tool that fetches URLs is a tool somebody will aim at us
Anyone can ask us to fetch any address, which makes this service a natural lever for reaching infrastructure rather than the public web: cloud metadata endpoints, internal admin panels, database ports.
Every address is resolved and checked before a connection is made, and the connection goes to the address that was checked rather than being resolved again, which would reopen the window between the two. Private, loopback, link-local and metadata ranges are refused. Every redirect is re-checked, because a public URL that redirects to an internal one is the standard way around a guard that only looks at what it was given.
Accounts and sessions
Passwords are hashed with bcrypt at a work factor chosen to be slow, and never stored or logged in a form we could read. A sign-in attempt for an address that does not exist still does the hashing work, so the time a response takes cannot be used to learn which addresses are registered.
Session cookies are HTTPS-only and closed to JavaScript, so a scripting bug cannot read one. The session identifier is regenerated when you sign in, which is what stops an identifier planted before authentication being usable after it. Every form that changes something carries a token checked in constant time.
Signing in with Google is available and uses it only to confirm the address. We never receive your Google password.
The headers we send
This product audits other sites for the response headers a browser uses to defend a page, so it sends them itself: a content security policy that refuses inline scripts other than one we name explicitly, HSTS, nosniff, two separate refusals to be framed, a referrer policy that keeps report addresses off third party sites, and a permissions policy switching off the device APIs nothing here uses.
You can check that claim the way you would check anyone else's. Run our own analyzer on us.
Payments
We never see a card. Payment happens on the provider's own pages and we receive a confirmation, so there is no card number in our database to lose. Plans change only when the provider confirms the money arrived, never when a browser returns from one, because a URL anyone can construct is not evidence of payment.
What we keep
The reports you run and the HTML of the pages as fetched, so a report can be reopened without crawling the page again. Your account, your workspaces and who you invited to them.
A report lives at an address with a random key in it and no sign-in, so anyone you send the link to can read it. Reports are not listed anywhere and are marked so search engines leave them out. Your history and tracked pages are not: those need you to be signed in.
Deleting your account removes it and the workspaces you own. See Privacy for what that covers and GDPR for the rights behind it.
Telling us about a problem
If you have found something, please tell us before telling anybody else, and give us a way to reach you. Write to our contact page with enough detail to reproduce it.
We will confirm we received it, tell you what we found when we have looked, and credit you if you would like to be named. We do not run a paid bounty, and we would rather hear about something small than not hear about it.