
Security
We read your website. That’s it.
AgencyProof is a reading tool. It fetches the public pages of the site you point it at, the way a browser would, and writes down what it finds. This page is the complete inventory of what that involves.
This page is about how we handle your data. AgencyProof is not a security audit of your site, not a penetration test, and not a vulnerability scan.
01What we access
Public pages only.
A scan fetches a bounded sample of reachable public pages — the homepage, the pages it links to, and the paths visitors expect to exist, like /contact and /privacy. Anything a logged-out visitor can see, we can inspect. Anything they can’t, we don’t touch.
One tier goes further, and it matters here. Inspects selected pages in a real rendered browser, after JavaScript has run. That is a Launch Audit only — on every other tier no browser is opened and no JavaScript is executed.
Public-page inspection; authenticated areas are out of scope. No payment details are entered and no transaction is completed. Forms are located and inspected, never filled in or sent.
There is nothing to install and nothing to hand over. No snippet, no plugin, no DNS change, no access to your hosting — and we never ask for credentials of any kind: no CMS login, no hosting password, no API key. Paste a URL; that is the entire integration.
02What we store
The findings, and the text they came from.
We keep the parsed text and metadata of the pages we scanned, the issues the inspection produced, the scores, and the report. That record exists so you can compare scans over time and re-open old reports.
It is deletable. Remove a project and its scans, pages, issues, and reports are removed with it. We store no data about your site’s visitors, because we never meet them.
03What we never do
The short list of hard no’s.
The other half of the access log is the half that never prints. Each of these is refused before it can happen — not a policy we promise to follow, a request the scanner simply never makes.
04Infrastructure
Boring on purpose.
AgencyProof runs on Vercel. Data lives in Supabase (Postgres) with row-level security, so every organization’s projects, scans, and reports are isolated at the database layer — not just in application code. Data is encrypted in transit and at rest.
Lead-form submissions are write-only from the public site: the page that collects your email cannot read anyone else’s.
05AI review
Page content only, and always labeled.
The AI-assisted layer reads the same public page text the crawler collected — nothing else. No account data, no email addresses, no scan history leaves our infrastructure.
AI-assisted diagnostics and implementation guidance, with the method and confidence shown in the report. Findings include a confidence and method label. So an AI-derived observation is never presented as a deterministic check result, and you can tell the two apart in the report itself.
06Responsible disclosure
Found something? Tell us first.
If you find a security issue in AgencyProof itself, we want to hear about it before the internet does. This is about our product, not a service we perform on yours.
support@agencyproof.ai
Include what you found and how to reproduce it. A human reads and answers every report, credits researchers who want credit, and never takes legal action against good-faith research.
Security questions that aren’t disclosures — how scans handle your data, a procurement or vendor review — reach the same people at that address, or through the contact page.