Security and data protection
Agent Checker drives a real browser across your live website, so it is fair to ask what we touch and what we keep. This page answers that, including the questions where the answer is no.
Run a free Quick checkCertifications and compliance, straight answers
UK GDPR and EU GDPR
Yes
CodeHawks Limited is a UK data controller and processes personal data under UK GDPR and EU GDPR. The legal bases, your rights and how to exercise them are set out in the Privacy Policy.
SOC 2 and ISO 27001
Not certified
We hold neither a SOC 2 report nor an ISO 27001 certificate today, and we would rather say so than leave you guessing. The controls we do operate are described below, and we will answer a security questionnaire on request.
What we hold
Your account
An email address, your workspace and team membership, and your plan. We never store a password: sign-in is a one-time code sent to your email, or Google OAuth.
Your audits
The URLs you submit, the report we generate, and the screenshots the agent captured while browsing. Reports and screenshots are held in a private, access-controlled object store, and are retained so your audit history and score trend stay available to you. They are deleted on request. If you need the storage region confirmed in writing for a procurement review, ask and we will confirm it.
Your support chat
If you use the chat bubble, the email address you give and the messages you send. They reach us as a thread in our Slack workspace so we can reply. Our copy of the transcript is deleted automatically after 30 days.
What we never hold
Card details, which go directly to Stripe and never reach our servers. Credentials for your site: audits run as an anonymous visitor, so you never hand us a login. And no customer data from your site beyond what a public page already shows to anyone.
How it is protected
- Every page and API endpoint is served over HTTPS with HSTS and a preloaded policy. There is no plaintext route into the product.
- Data at rest is encrypted by our database and object-storage providers.
- Sign-in uses a one-time email code or Google OAuth. No passwords exist to leak.
- Access to production data is limited to the people who operate the service, and administrative surfaces sit behind a separate authorisation check.
- Audits browse your site as an anonymous visitor. The runner is prevented from following links off your domain.
- Dependencies are scanned for known vulnerabilities on every pull request, and a scan failure blocks the merge.
Sub-processors
The third parties that process data on our behalf, and what each one is for.
| Provider | Purpose |
|---|---|
| Vercel | Front-end hosting and CDN |
| Railway | Application servers, audit runner and PostgreSQL database |
| Supabase | Authentication only. No application data is stored there |
| Anthropic | The Claude model that drives the audit agent |
| Browserbase | Headless browser infrastructure that runs audits |
| Stripe | Payments and subscription billing |
| Resend | Transactional and report email |
| PostHog | Product analytics |
| Sentry | Error monitoring |
| Slack | Where support chat messages reach us, so we can answer them |
Reporting a vulnerability
Email hello@agentchecker.ai with the subject line "Security report". We acknowledge within one working day and will keep you updated until it is closed. Please give us a reasonable window to fix an issue before disclosing it publicly. We will not pursue anyone who reports in good faith.
Need a security questionnaire completed?
Send it over and we will fill it in, including the parts where the honest answer is "not yet".
Contact support