Security

Trust Center

How AtRisk protects customer data for URL and repo security assurance. Honest controls we operate, without certification theater.

Last updated: September 9, 2026 · Effective: September 9, 2026

1. Scope

This page covers atrisk.dev, app.atrisk.dev, and related AtRisk APIs and Workers. Legal terms live in our Privacy Policy and Terms of Service.

We do not claim SOC 2, ISO 27001, PCI DSS, or similar certifications on this page. When we complete an independent audit, we will say so explicitly.

2. Infrastructure and transport

  • TLS for traffic to atrisk.dev and app.atrisk.dev (HTTPS enforced)
  • Application and marketing sites served on Cloudflare (CDN, Workers, related edge controls)
  • Application data stored in Neon (managed Postgres / auth infrastructure)
  • Secrets and API keys kept in platform secret stores - not committed to source control

3. Authentication and access

  • Account authentication via Neon Auth (email/password and supported OAuth)
  • Session-based access to customer workspaces and Findings
  • MCP tokens are account credentials - you can create and revoke them in-product
  • Team invites and seat membership control who can see shared Customer Content
  • Operator access to Cloudflare, Neon, GitHub, and billing consoles is limited to people who need it; MFA is required for those operator accounts where the vendor supports it

4. Application security controls

  • URL scanning is designed as read-only retrieval of publicly reachable resources you authorize
  • SSRF and abuse protections on scan and tool endpoints (block private/link-local targets, rate limits)
  • API and free-tool rate limiting (including Cloudflare KV–backed limits on the marketing site)
  • Input validation and auth checks on Worker API routes
  • Error monitoring via Sentry (errors and performance traces; session replay sample rates set to zero)
  • Product analytics via PostHog (usage events; session recording not enabled in current configuration)
  • Reddit Pixel on atrisk.dev for Reddit Ads conversion measurement; skipped when the browser sends Global Privacy Control

We removed Microsoft Clarity from the marketing site. We do not run marketing-site session replay or heatmaps.

5. Data retention (indicative)

  • Operational scan / agent / audit records - typically about 90 days under automated retention, unless longer retention is required for disputes, security, or law
  • Free-tool lead records in Cloudflare KV - about 90 days, refreshed when the same email is reused
  • Account and billing metadata - for the life of the account and as required for tax/commercial records

Details are in the Privacy Policy (Section 9).

6. Subprocessors

We use vetted infrastructure and SaaS providers to run AtRisk. The live list is on /subprocessors, mirroring Privacy Policy §8.

7. Vulnerability disclosure

Report security issues to contact@atrisk.dev. Our vulnerability disclosure policy describes safe harbor expectations and our 90-day coordinated disclosure approach. Also see /.well-known/security.txt.

8. Privacy and DSAR

Requests

Privacy and data-subject requests: contact@atrisk.dev. Where offered in-product, account holders can download a copy of their data from profile settings.

9. Contact

This Trust Center describes current engineering and operational practices as of September 9, 2026. It is not a SOC 2, ISO 27001, or other third-party certification attestation.