Security

What we do with your data, in plain terms

Scanning is read-only

We load your public pages the way a visitor's browser would and read the rendered result. We never write to your site, inject a script, or hold credentials for it.

No write access

Passwords are hashed, then screened

Stored with bcrypt at cost 12, never in readable form. New passwords are checked against known breach corpora using a k-anonymity lookup, so the password itself never leaves our server.

bcrypt cost 12 + breach screening

Changing your password ends other sessions

Every session carries a version stamp. Changing your password or confirming a new email address increments it, which invalidates every token issued before that moment.

Real session invalidation

Email changes are verified

A new address is held aside until a single-use link sent to it is opened, and your current address is told the change was requested. Only a hash of each link is stored.

Single-use, 1 hour expiry

Your data is not training data

Scan results are yours. We don't sell them, share them, or use them to train models. Deleting your account deletes your sites, scans and findings with it.

No model training

We scan ourselves

Allcess runs its own scanner against this site. It found genuine problems, including a primary button below the contrast threshold, and those were fixed before this page shipped.

0 findings on our own pages

Not yet

What we don't have

Larger vendors list certifications here. We don't have them yet, and implying otherwise would be exactly the behaviour this product exists to contrast with.

  • No SOC 2 report. We're too early to have been audited.
  • No single sign-on or SAML yet.
  • No configurable data region. Data lives where the app is hosted.
  • No published uptime SLA.

If any of these are blockers for you, say so at [email protected]. Knowing which ones actually cost us customers is the fastest way for them to get built.

Get started

See what's actually on your site

Add a URL and get a scan back in minutes. No plugin, no code on your site, no sales call.

  • Crawls your whole storefront, not just the homepage
  • Findings grouped by fix, not by page
  • Fix guidance tailored to Shopify and WooCommerce
  • A dated PDF record of every scan