Skip to content

Trust

Security & privacy

You're trusting us with a record of your accessibility posture. Here's how we keep it safe — and what we deliberately don't collect.

Tenant isolation

Every organization's sites, scans and data are scoped to its own account. No customer can see another's data — enforced on every query and every API route, not just in the UI.

We only read public pages

The scanner loads your public URLs the same way a browser does. We don't ask for your CMS logins, database, or server access to do our job.

API keys are hashed

We store only a SHA-256 hash of each API key — never the key itself. A key is shown once at creation and can be revoked instantly.

Encryption in transit

All traffic runs over HTTPS/TLS. Sessions are signed, HTTP-only cookies, and integrations authenticate with bearer tokens.

Least data by design

We keep scan results and remediation history — not your visitors' personal data. There's no tracking pixel and no resale of data.

Monitored & backed up

The platform itself is monitored for uptime and SSL health, and databases are backed up regularly so your history is safe.

Working toward formal SOC 2 attestation. Have a security questionnaire or need a DPA? [email protected]

Ready to prove you're compliant?

Scan a page free, or start a 14-day trial and put every site on autopilot.