Security at the Core
Submitted text is encrypted in transit, analysed, and discarded. It is not written to a database and it is not used for training. One thing to be aware of: scoring runs through a third-party API, so your text is sent there to be analysed.
TLS/SSL Encryption
All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS) 1.2 or newer. We aim for an A+ rating on Qualys SSL Labs.
Ephemeral Processing
Your text is processed in volatile memory (RAM) and is never written to disk or a database. Once the analysis is complete, the data is instantly overwritten.
Third-party processing
Scoring is performed by a third-party detection API, so text you submit is transmitted to that provider over an encrypted connection in order to be analysed. We do not hold any certification such as SOC 2 or ISO 27001, and we will not imply otherwise.
No accounts, no stored text
There are no user accounts, so there is no profile linking a scan to a person, and no archive of submitted text to breach. The smallest attack surface is the one where the data is not kept.
Dependencies kept current
We patch the server runtime and application dependencies as updates ship. We do not currently commission third-party penetration testing, which is why the disclosure route below matters — reports from users are how most issues reach us.
Access Controls
We employ the Principle of Least Privilege. Staff access to production systems is restricted by MFA and VPNs, and logged for auditing purposes.
Responsible Disclosure
If you believe you've found a security vulnerability in our service, please tell us. We look forward to working with you to resolve the issue promptly.
[email protected]