Skip to main content
How we handle your text

Security at the Core

Submitted text is encrypted in transit, analysed, and discarded. It is not written to a database and it is not used for training. One thing to be aware of: scoring runs through a third-party API, so your text is sent there to be analysed.

TLS/SSL Encryption

All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS) 1.2 or newer. We aim for an A+ rating on Qualys SSL Labs.

Ephemeral Processing

Your text is processed in volatile memory (RAM) and is never written to disk or a database. Once the analysis is complete, the data is instantly overwritten.

Third-party processing

Scoring is performed by a third-party detection API, so text you submit is transmitted to that provider over an encrypted connection in order to be analysed. We do not hold any certification such as SOC 2 or ISO 27001, and we will not imply otherwise.

No accounts, no stored text

There are no user accounts, so there is no profile linking a scan to a person, and no archive of submitted text to breach. The smallest attack surface is the one where the data is not kept.

Dependencies kept current

We patch the server runtime and application dependencies as updates ship. We do not currently commission third-party penetration testing, which is why the disclosure route below matters — reports from users are how most issues reach us.

Access Controls

We employ the Principle of Least Privilege. Staff access to production systems is restricted by MFA and VPNs, and logged for auditing purposes.

Responsible Disclosure

If you believe you've found a security vulnerability in our service, please tell us. We look forward to working with you to resolve the issue promptly.

[email protected]