Security & transparency
Our own EU infrastructure, no hyperscaler, GDPR-compliant. What we check, what we store, and what we do not.
Infrastructure
Everything we operate ourselves is located in the EU: scanners, database, monitoring and email dispatch. No AWS, no Google Cloud, no Azure. Where we use service providers, they are listed together with their location in the privacy policy and in the list of sub-processors — some of them with a third-country element, payment processing above all.
What our scanners do — and what they do not
What our scanners do
- Request the web address you enter over HTTP(S) and make selected additional requests
- Analyse the publicly available response headers
- Query DNS records via DoH (DNS over HTTPS)
- Open an SMTP connection for email protocol checks
What our scanners do NOT do
- No penetration tests and no active attacks
- No enumeration of directories or files
- No site-wide crawling
- No storage of the content of your website
- No access to protected areas
Legal basis: our scanners work like an ordinary browser request. Only publicly accessible information is checked.
Our own security
We scan ourselves — with the same tools our customers use. Current score: check it yourself →
What we check against
Questions about security?
Transparency matters to us. If you have questions about our infrastructure, our data processing or how the scanners work: get in touch.