Trust & security

A small footprint, on purpose.

We hold as little as we can, and we're specific about what that is. Here's exactly what we collect, what we don't, and why.

We read only public content

Our products read what's already public — a site's help center, its public pages, its robots and security surface. Nothing behind a login, and generally no personal data.

We collect only what we need

An email to deliver your report, and the report itself. The link we email is a permanent, shareable token, so anyone who has it can open the report — treat it like a password. We may email you occasional follow-ups; you can opt out any time, and we delete what we hold on request.

We don’t train on your data

The Anthropic API doesn’t train on your content by default, and neither do we. Your content produces your result. For product benchmarks we keep category-level outcomes keyed to a one-way hash of your domain: pseudonymous and domain-linked, not fully anonymous. We don’t keep a full copy of your pages; the report keeps only the specific passages it cites as evidence.

On engagements, we sign first

Consulting work runs under your NDA and MSA. Client data and IP are yours, kept only as long as the engagement needs, and handled on least-access terms.

Secrets stay in the environment

API keys and credentials live in managed environment variables, separated per environment, never in source control.

Questions about data handling, retention, or a specific engagement? Ask us directly.