Skip to content
OkayToShip

How we handle your data

We check other people's apps for leaks, so we hold ourselves to the same rules. Here they are.

We don't store the secrets we find

When we find a key or token in your code, we keep only its type and the first 6 characters, for example sk_liv…. That's enough for you to recognise it. The full value is never written to our database, our logs or your report.

A key that was public is still compromised. The report tells you how to replace it.

We don't attack sites

A free scan does only what a browser does: it loads pages and scripts, reads headers and looks up DNS. It doesn't sign in, submit forms, guess passwords or send attack payloads.

Checks that touch your data, like testing your database rules, run only after you verify that you own the app. Passive and active checks

Sites we never scan

Government, military, banking, healthcare and education sites, even if someone asks.

IP addresses, internal hostnames and private networks. We check public domains only.

Every domain has a daily limit of free scans, and each scan needs a quick bot check.

Payments

Card payments go to Lemon Squeezy, our merchant of record. We never see or store card details.

Found a problem in OkayToShip?

Tell us. Our responsible disclosure policy explains how to report it and what we promise in return.