Security
How AtRisk protects customer data for URL and repo security assurance. Honest controls we operate, without certification theater.
Last updated: September 9, 2026 · Effective: September 9, 2026
This page covers atrisk.dev, app.atrisk.dev, and related AtRisk APIs and Workers. Legal terms live in our Privacy Policy and Terms of Service.
We do not claim SOC 2, ISO 27001, PCI DSS, or similar certifications on this page. When we complete an independent audit, we will say so explicitly.
We removed Microsoft Clarity from the marketing site. We do not run marketing-site session replay or heatmaps.
Details are in the Privacy Policy (Section 9).
We use vetted infrastructure and SaaS providers to run AtRisk. The live list is on /subprocessors, mirroring Privacy Policy §8.
Report security issues to contact@atrisk.dev. Our vulnerability disclosure policy describes safe harbor expectations and our 90-day coordinated disclosure approach. Also see /.well-known/security.txt.
Privacy and data-subject requests: contact@atrisk.dev. Where offered in-product, account holders can download a copy of their data from profile settings.
Contact: contact@atrisk.dev