Skip to content

Security and data protection

Agent Checker drives a real browser across your live website, so it is fair to ask what we touch and what we keep. This page answers that, including the questions where the answer is no.

Run a free Quick check

Certifications and compliance, straight answers

UK GDPR and EU GDPR

Yes

CodeHawks Limited is a UK data controller and processes personal data under UK GDPR and EU GDPR. The legal bases, your rights and how to exercise them are set out in the Privacy Policy.

SOC 2 and ISO 27001

Not certified

We hold neither a SOC 2 report nor an ISO 27001 certificate today, and we would rather say so than leave you guessing. The controls we do operate are described below, and we will answer a security questionnaire on request.

What we hold

Your account

An email address, your workspace and team membership, and your plan. We never store a password: sign-in is a one-time code sent to your email, or Google OAuth.

Your audits

The URLs you submit, the report we generate, and the screenshots the agent captured while browsing. Reports and screenshots are held in a private, access-controlled object store, and are retained so your audit history and score trend stay available to you. They are deleted on request. If you need the storage region confirmed in writing for a procurement review, ask and we will confirm it.

Your support chat

If you use the chat bubble, the email address you give and the messages you send. They reach us as a thread in our Slack workspace so we can reply. Our copy of the transcript is deleted automatically after 30 days.

What we never hold

Card details, which go directly to Stripe and never reach our servers. Credentials for your site: audits run as an anonymous visitor, so you never hand us a login. And no customer data from your site beyond what a public page already shows to anyone.

How it is protected

  • Every page and API endpoint is served over HTTPS with HSTS and a preloaded policy. There is no plaintext route into the product.
  • Data at rest is encrypted by our database and object-storage providers.
  • Sign-in uses a one-time email code or Google OAuth. No passwords exist to leak.
  • Access to production data is limited to the people who operate the service, and administrative surfaces sit behind a separate authorisation check.
  • Audits browse your site signed out, with no credentials and no access to anything a member of the public cannot already see. The runner is prevented from following links off your domain.
  • The audit session presents as a standard desktop Chrome, because that is what the AI agents we measure drive, and your CDN needs to serve us the page it serves them. If you would rather it announced itself, ask for a declared audit and it will identify as AgentCheckerBot instead.
  • Dependencies are scanned for known vulnerabilities on every pull request, and a scan failure blocks the merge.

Who processes your data

We use a small number of third-party service providers to run the product, each under contract and only on our instructions. They are listed, with the purpose of each, in the Privacy Policy.

Reporting a vulnerability

Email hello@agentchecker.ai with the subject line "Security report". We acknowledge within one working day and will keep you updated until it is closed. Please give us a reasonable window to fix an issue before disclosing it publicly. We will not pursue anyone who reports in good faith.

Need a security questionnaire completed?

Send it over and we will fill it in, including the parts where the honest answer is "not yet".

Contact support