SECURITY PRACTICES
Security is a product feature.
- Raw identifiers are never placed in URLs or scan logs.
- Inputs are strictly validated and requests are rate-limited.
- Security and privacy links use an HTTPS first-party allowlist.
- Responses preserve unknown and provider-failure states rather than reporting a false clean result.
This preview is not a production security certification. See SECURITY.md for deployment requirements.