GapStudy / Service information

Security

Updated 19 September 2026. This operational notice requires owner and legal review before paid launch. It is not a certification or a negotiated data-processing agreement.

Public requests only

The scanner accepts HTTP and HTTPS websites on standard ports. Private, loopback, reserved and metadata addresses are blocked. Each redirect is revalidated and each network connection is pinned to a verified public address.

Bounded analysis

Requests have response-size and time limits. A study inspects at most five primary pages and two explicitly selected competitor pages. Robots restrictions, daily admission limits and global concurrency limits are enforced. Forms are never submitted and page scripts are never executed.

Report access

Account studies use the existing Supabase authentication system. Guest studies use a random, HTTP-only browser capability cookie. Studies are private until an owner creates a revocable share link. Database row policies restrict direct authenticated reads to the owning account.

Untrusted content

Website content is treated as evidence, not instructions. Deterministic rules generate findings and validate their evidence references. No website text can initiate external actions or access environment credentials.

Limitations and disclosure

No security certification or independent audit is claimed. Please report suspected security issues through the support address below, without including passwords, secrets or other people's private records.

Questions or data requests: hello@clientflow.app