Skip to content

Security and data protection

Agent Checker drives a real browser across your live website, so it is fair to ask what we touch and what we keep. This page answers that, including the questions where the answer is no.

Run a free Quick check

Certifications and compliance, straight answers

UK GDPR and EU GDPR

Yes

CodeHawks Limited is a UK data controller and processes personal data under UK GDPR and EU GDPR. The legal bases, your rights and how to exercise them are set out in the Privacy Policy.

SOC 2 and ISO 27001

Not certified

We hold neither a SOC 2 report nor an ISO 27001 certificate today, and we would rather say so than leave you guessing. The controls we do operate are described below, and we will answer a security questionnaire on request.

What we hold

Your account

An email address, your workspace and team membership, and your plan. We never store a password: sign-in is a one-time code sent to your email, or Google OAuth.

Your audits

The URLs you submit, the report we generate, and the screenshots the agent captured while browsing. Reports and screenshots are held in a private, access-controlled object store, and are retained so your audit history and score trend stay available to you. They are deleted on request. If you need the storage region confirmed in writing for a procurement review, ask and we will confirm it.

Your support chat

If you use the chat bubble, the email address you give and the messages you send. They reach us as a thread in our Slack workspace so we can reply. Our copy of the transcript is deleted automatically after 30 days.

What we never hold

Card details, which go directly to Stripe and never reach our servers. Credentials for your site: audits run as an anonymous visitor, so you never hand us a login. And no customer data from your site beyond what a public page already shows to anyone.

How it is protected

  • Every page and API endpoint is served over HTTPS with HSTS and a preloaded policy. There is no plaintext route into the product.
  • Data at rest is encrypted by our database and object-storage providers.
  • Sign-in uses a one-time email code or Google OAuth. No passwords exist to leak.
  • Access to production data is limited to the people who operate the service, and administrative surfaces sit behind a separate authorisation check.
  • Audits browse your site as an anonymous visitor. The runner is prevented from following links off your domain.
  • Dependencies are scanned for known vulnerabilities on every pull request, and a scan failure blocks the merge.

Sub-processors

The third parties that process data on our behalf, and what each one is for.

ProviderPurpose
VercelFront-end hosting and CDN
RailwayApplication servers, audit runner and PostgreSQL database
SupabaseAuthentication only. No application data is stored there
AnthropicThe Claude model that drives the audit agent
BrowserbaseHeadless browser infrastructure that runs audits
StripePayments and subscription billing
ResendTransactional and report email
PostHogProduct analytics
SentryError monitoring
SlackWhere support chat messages reach us, so we can answer them

Reporting a vulnerability

Email hello@agentchecker.ai with the subject line "Security report". We acknowledge within one working day and will keep you updated until it is closed. Please give us a reasonable window to fix an issue before disclosing it publicly. We will not pursue anyone who reports in good faith.

Need a security questionnaire completed?

Send it over and we will fill it in, including the parts where the honest answer is "not yet".

Contact support