§ Security · how we handle your data

Security policy.

Responsible disclosure, how we treat the data you send us, and the things we don't keep.

Responsible disclosure

If you find a vulnerability, email [email protected]. Please give us 48 hours to acknowledge before public disclosure. We don't run a bug bounty — we do send thank-you notes, shout-outs, and stickers.

Encrypt sensitive details with our PGP key if needed.

Please do

Pentest against your own account. Don't scan or attempt to exploit other customers' data or infrastructure — we'll share test domains if you need them.

Transport

Authentication

SSRF protection

Every URL-fetching endpoint (screenshot, PDF, scrape, SEO, diff, broken-links, link-preview) validates the target:

Data retention

Vendors & subprocessors

Compliance

Contact

Security issues: [email protected]. Everything else: [email protected].