Trust
Security & privacy
You're trusting us with a record of your accessibility posture. Here's how we keep it safe — and what we deliberately don't collect.
Tenant isolation
Every organization's sites, scans and data are scoped to its own account. No customer can see another's data — enforced on every query and every API route, not just in the UI.
We only read public pages
The scanner loads your public URLs the same way a browser does. We don't ask for your CMS logins, database, or server access to do our job.
API keys are hashed
We store only a SHA-256 hash of each API key — never the key itself. A key is shown once at creation and can be revoked instantly.
Encryption in transit
All traffic runs over HTTPS/TLS. Sessions are signed, HTTP-only cookies, and integrations authenticate with bearer tokens.
Least data by design
We keep scan results and remediation history — not your visitors' personal data. There's no tracking pixel and no resale of data.
Monitored & backed up
The platform itself is monitored for uptime and SSL health, and databases are backed up regularly so your history is safe.
Working toward formal SOC 2 attestation. Have a security questionnaire or need a DPA? [email protected]
Ready to prove you're compliant?
Scan a page free, or start a 14-day trial and put every site on autopilot.