Skip to content
Pandus

Security and data protection

Your data is hosted in the European Union, our scanner runs isolated from the rest of the system, all connections are encrypted, backups are tested, and our website does not use tracking cookies. Below is how this works in practice.

Hosting in the EU

The application, database, scan results and reports are hosted on servers in the European Union. Where we use third-party services that are based elsewhere (for example a payment provider), they are listed in our list of sub-processors, and we choose their EU region where one exists.

An isolated scanner

A scanner is a browser that opens addresses on request — so it needs special care.

  • It runs as a separate, sandboxed process with no access to our database, secrets or customer files.
  • It talks to the application only through a restricted job queue; jobs are signed, and unsigned or old jobs are rejected.
  • It may only connect to the public internet. Connections to private, local and internal network addresses are blocked by the firewall as well as by the scanner itself.

SSRF protection and limits

  • Only http and https on the standard ports 80 and 443.
  • Before the browser opens a page, and again after every redirect, the address is resolved and checked; private, local and reserved IP ranges are rejected.
  • Page timeouts, a limit on redirects and on page size, and no file downloads.
  • The free check is protected by a bot challenge and rate limits per IP address and email, and results are cached for 24 hours.
  • These cases are covered by automated tests.

Encryption and access

  • All traffic to our site and app uses TLS.
  • Sensitive credentials are stored encrypted.
  • Two-factor authentication is available for all accounts and required for our own administrators.
  • Team data is separated: one customer cannot see another customer's sites, scans or files, and this isolation is covered by tests.
  • Administrative actions are recorded in an audit log.

Backups

The database is backed up daily, and backups are copied to separate storage in the EU. Every month we automatically restore a backup into a test database to make sure it actually works.

Data we keep and for how long

We scan public pages, which normally contain little personal data. Screenshots from scheduled scans are deleted after 90 days and screenshots from free checks after 7 days. Logs are kept for a limited time. You can request an export or deletion of your account data.

No tracking cookies

Our public website does not set marketing or tracking cookies. We measure visits with privacy-friendly, cookieless statistics. If that ever changes, we will ask for your consent first.

What our scans are — and are not

Security and honesty go together: our scans test public pages for accessibility issues only. They are an automated check, not a full audit, and not legal advice, and they never try to log in, submit forms or probe your site for security weaknesses.

Report a vulnerability

If you think you have found a security issue, please write to us via the contact page and do not test against other customers' data. We reply within two working days.

Related: our accessibility statement and about us.