About the scan
If you received a note from us, here is exactly what happened and why, in plain terms.
What we looked at
Only what your app already serves to any visitor: your public pages, your front-end JavaScript, your source maps, and your response headers. The same things a browser downloads when anyone opens your site.
What we did not do
We did not log in. We did not use any key or credential. We did not change anything, and we did not access your users' data. If we noticed an exposed value, it is redacted in your report and we do not store it.
Why we reached out
We found something worth fixing, and we told you privately, before anyone else. That is the whole point. There is no threat and no deadline. If it is useful, great. If not, you can ignore us.
How to stop scans
Reply to our message, or email [email protected] with your domain, and we will exclude it. We respect robots directives and a security.txt contact where present.
Want to run a check on an app you own?
Run a free check