Privacy
The principle
A security tool that accumulated a map of its clients' sites would be a prime target. Our answer is not to protect that data better: it is not to keep it at all.
What passes through during an analysis
To analyse a site, our servers receive the list of its file paths and their fingerprints, along with the content of public pages and of files whose content must be examined. These elements are used to compute your report.
They are not kept after the analysis: the report is returned to you, and nothing is stored on our side. That is also why we cannot send you an old report — we no longer have it. This holds for the Record analysis; Watch, for its part, keeps a record, described below.
Your FTP or SSH credentials
The external analysis does not need it: an address is enough. The analysis of your server, however, must place its agent there, and there are two ways to do it:
- You entrust us with your credentials for the duration of the analysis: they are used to deploy the agent and then to remove it, and are never retained — neither written to a log, nor kept for next time. Next time, you provide them again.
- Or you deploy the agent yourself: your credentials are then never transmitted to us.
What Watch keeps
A Record analysis leaves nothing with us. Watch, on the other hand, has to keep a record: without it, it could neither name the file that changed, nor date its arrival, nor recognise the same bytes on another of your sites. Here is what that record contains, in full.
- Your site’s address, and the contact the alerts are sent to.
- The address of the agent installed on your server, and your site’s root.
- The reference fingerprint of the inventory, and the list of paths and fingerprints of your executable files.
- The destinations your page actually contacted during earlier passes.
- The date each unexplained file first appeared: that is what makes it possible to date an arrival instead of merely noting it.
- The chained log of the passes: each night is written after the one before it.
That record lives for as long as Watch runs, and no longer: when it stops — at the end of the year, or the same day if you stop it earlier — the record is deleted. We host it ourselves, with our hosting provider, in Europe, outside the web root.
What stays with you
- Your orders, your customers and their contact details, your carts, your payment methods, your passwords and your messages.
- The content of your backups.
What the basic examination looks at
When you entrust us with an analysis of your server, part of your file tree is examined — and only part. The list of locations is written into the agent placed on your side, never in our service: nothing coming from us can widen it.
- The options and settings, rendered across all your pages.
- The content of posts and pages.
- The custom fields used by the templates.
- Accounts that can do anything: their number, their role, their date. Never their login name, never their address, never their password hash.
- Scheduled tasks, the site's declared address, and the list of active extensions.
And the rule that makes the rest true by design: only a value containing executable code can be reported, and only the fragment surrounding that code. A customer's address looks nothing like executable code — so it triggers nothing, and never leaves. This is not a policy we impose on ourselves, it is a consequence of the way the examination is written.
The verification page
It receives nothing. Verifying a document's signature takes place entirely in the browser of the person checking it: the document is not sent anywhere, and no trace of it is kept.
Your customer data
When you make a purchase, we process the data required for the order and invoicing (email address, payment information handled by Stripe, domain of the site concerned for licences). It is retained for as long as our accounting obligations require.
Subprocessors
- Stripe Payments Europe, Ltd. — online payment.
- Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, United States — site hosting and running the analyses.
Cookies
This site uses no analytics or advertising cookies. Only strictly necessary technical cookies may be placed during a payment, by Stripe.
Your rights
You have a right of access, rectification, erasure and objection regarding your data. Write to contact@aiwebsitesecurity.com. Data controller: EUROPE TECHNOLOGIE, 133 avenue Gambetta, 75020 Paris, France. You may also lodge a complaint with the CNIL.