Skip to content
AgencyProofby Intelliblitz
Inspector Dot stands calmly beside a closed navy vault door drawn as a browser window, a green checkpoint lamp glowing above it.

Security

We read your website. That’s it.

AgencyProof is a reading tool. It fetches the public pages of the site you point it at, the way a browser would, and writes down what it finds. This page is the complete inventory of what that involves.

This page is about how we handle your data. AgencyProof is not a security audit of your site, not a penetration test, and not a vulnerability scan.

NO TRACKING SCRIPT
Pixel Pigeon rushing a photo card toward the Privacy Checkpoint, its revealing filename trailing behind it
privacy checkpoint · potentially revealing image filenames

01What we access

Public pages only.

A scan fetches a bounded sample of reachable public pages — the homepage, the pages it links to, and the paths visitors expect to exist, like /contact and /privacy. Anything a logged-out visitor can see, we can inspect. Anything they can’t, we don’t touch.

One tier goes further, and it matters here. Inspects selected pages in a real rendered browser, after JavaScript has run. That is a Launch Audit only — on every other tier no browser is opened and no JavaScript is executed.

Public-page inspection; authenticated areas are out of scope. No payment details are entered and no transaction is completed. Forms are located and inspected, never filled in or sent.

There is nothing to install and nothing to hand over. No snippet, no plugin, no DNS change, no access to your hosting — and we never ask for credentials of any kind: no CMS login, no hosting password, no API key. Paste a URL; that is the entire integration.

ACCESS LOG
RECEIPT № 2537 · LAUNCH INSPECTION BUREAU
GET public pages (≤35)
read page HTML + metadata
read links, images, JSON-LD
render ≤12 pages · Launch Audit
probe /contact · /privacy
probe robots.txt · sitemap
KEEP FOR YOUR RECORDS

02What we store

The findings, and the text they came from.

We keep the parsed text and metadata of the pages we scanned, the issues the inspection produced, the scores, and the report. That record exists so you can compare scans over time and re-open old reports.

It is deletable. Remove a project and its scans, pages, issues, and reports are removed with it. We store no data about your site’s visitors, because we never meet them.

03What we never do

The short list of hard no’s.

The other half of the access log is the half that never prints. Each of these is refused before it can happen — not a policy we promise to follow, a request the scanner simply never makes.

REFUSED · NEVER RUN
RECEIPT № 5913 · LAUNCH INSPECTION BUREAU
ask for logins or credentials
install tracking script
crawl behind a login
sell or share scan data
scrape beyond your site
train models on content
KEEP FOR YOUR RECORDS

04Infrastructure

Boring on purpose.

AgencyProof runs on Vercel. Data lives in Supabase (Postgres) with row-level security, so every organization’s projects, scans, and reports are isolated at the database layer — not just in application code. Data is encrypted in transit and at rest.

Lead-form submissions are write-only from the public site: the page that collects your email cannot read anyone else’s.

05AI review

Page content only, and always labeled.

The AI-assisted layer reads the same public page text the crawler collected — nothing else. No account data, no email addresses, no scan history leaves our infrastructure.

AI-assisted diagnostics and implementation guidance, with the method and confidence shown in the report. Findings include a confidence and method label. So an AI-derived observation is never presented as a deterministic check result, and you can tell the two apart in the report itself.

06Responsible disclosure

Found something? Tell us first.

If you find a security issue in AgencyProof itself, we want to hear about it before the internet does. This is about our product, not a service we perform on yours.

support@agencyproof.ai

Include what you found and how to reproduce it. A human reads and answers every report, credits researchers who want credit, and never takes legal action against good-faith research.

Security questions that aren’t disclosures — how scans handle your data, a procurement or vendor review — reach the same people at that address, or through the contact page.