SECURITY & DATA HANDLING
Security begins with limited access.
Evolize analyzes publicly accessible website surfaces without requiring source-code access, production credentials, installed agents or authentication bypass.
Last reviewed:
- Public surfaces only
- No credentials
- No installed agent
- No authentication bypass
01 — LIMITED ACCESS MODEL
The scanner is designed around a restricted access boundary.
Evolize evaluates the same public pages that customers, automated claim-generation systems and external reviewers can inspect. It does not require privileged access to internal systems.
Evolize may access
- Publicly reachable webpages
- Public page assets and browser responses
- Browser-rendered page output
- Publicly exposed technical metadata
- Public accessibility and interaction states
- Publicly observable responsive behaviour
Evolize does not require
- Source-code repositories
- Production or administrator credentials
- Customer databases
- Private network access
- Installed JavaScript or site agents
- Access to authenticated customer areas
02 — SCAN BEHAVIOUR
Public-surface scanning is bounded and non-invasive.
Evolize inspects externally observable website behaviour without attempting to exploit, alter or gain privileged access to the target environment.
- Scans stay within the configured public-page scope.
- Request concurrency is controlled to limit load.
- The scanner does not guess or test passwords.
- The scanner does not attempt to bypass authentication.
- The scanner does not exploit detected vulnerabilities.
- The scanner does not complete purchases or irreversible transactions.
- The scanner avoids state-changing form submissions.
- Authenticated and private-environment scanning is not supported.
- Website owners can report unexpected scan behaviour.
03 — DATA PROCESSED
Data is collected only where required to detect, reproduce and manage findings.
Each category below is processed for a specific operational reason. Example data is separated from the purpose it serves.
Scan data
Includes
- Submitted domain
- Public URLs inspected
- Browser and response metadata
- Page structure and rendered output
- Detected findings and severity
- Scan timestamps and scan status
Purpose
Used to perform the scan, determine scope and produce findings.
Evidence data
Includes
- Relevant screenshots or screenshot crops
- DOM or HTML fragments
- Stable selectors
- Accessibility-tree extracts
- Component fingerprints
- Responsive-state evidence
- Finding history and verification records
Purpose
Used to reproduce findings, support remediation and determine whether an issue has changed or returned.
Account and operational data
Includes
- User and organization details
- Authentication and session records
- Subscription and billing metadata
- Support communications
- Service logs
- Security and operational events
Purpose
Used to provide, secure, support and administer the Evolize service.
04 — EVIDENCE LIFECYCLE
Evidence follows a defined operational lifecycle.
From the submitted domain to retention or deletion, evidence moves through a fixed sequence of stages.
Domain submitted
The customer provides a domain or public URL for analysis.
Public pages retrieved
Evolize loads the permitted public pages within the configured scan scope.
Technical analysis
The scanner evaluates rendered output, accessibility states, responsive behaviour and other supported rules.
Evidence created
Relevant technical fragments and visual evidence are stored to support reproduction and remediation.
Retained or deleted
Evidence is retained according to the applicable plan and deletion policy, then removed when no longer required.
05 — RETENTION & DELETION
Retention rules are explicit and predictable.
Evolize retains scan evidence only for the period required to provide historical comparison, remediation verification and recurrence detection.
| Data category | Default retention |
|---|---|
| Customer-visible scan history | 12-month history on Single Website and Portfolio; custom on Enterprise |
Customer-visible scan history
- Default retention
- 12-month history on Single Website and Portfolio; custom on Enterprise
Backup deletion. When evidence is deleted, residual copies may remain in routine backups until they age out of the backup rotation. Backup copies are used only for disaster recovery and are not restored into active customer use.
Aggregated metrics. Anonymized or aggregated operational metrics that no longer identify a customer or website may be retained after deletion or account closure, and are used only to operate and improve the service.
06 — IMPLEMENTED SAFEGUARDS
Safeguards are listed only when they are operationally verified.
The controls below are implemented today. Additional safeguards are added to this list only after they are in place and confirmed — not in advance.
Transport
Encrypted transport
Connections to Evolize are served exclusively over HTTPS using modern TLS.
Environments
Environment separation
Production, preview and development are configured and deployed separately.
Scan scope
Restricted scan scope
Scanning is limited to configured, publicly accessible website surfaces and does not require privileged system access.
Data
Data minimization
Evolize limits collected and retained data to information required to provide, secure and operate the service.
07 — SUBPROCESSORS
Service providers are disclosed by function and data involvement.
Evolize relies on the providers below to operate the service. This list is updated when the set of providers changes.
| Provider | Service function | Data involved | Region | Documentation |
|---|---|---|---|---|
| Cloudflare | Hosting, edge delivery, browser rendering, processing and storage | Scan inputs, generated evidence and operational metadata | Global infrastructure; storage and processing locations depend on the configured Cloudflare services and account settings | Security documentation (opens in a new tab) |
| WorkOS, Inc. | Authentication, identity and organization management | User identity data, authentication identifiers, session metadata and organization membership data where applicable. | United States; international transfers may apply | Security and privacy documentation (opens in a new tab) |
Cloudflare
- Service function
- Hosting, edge delivery, browser rendering, processing and storage
- Data involved
- Scan inputs, generated evidence and operational metadata
- Region
- Global infrastructure; storage and processing locations depend on the configured Cloudflare services and account settings
- Documentation
- Security documentation (opens in a new tab)
WorkOS, Inc.
- Service function
- Authentication, identity and organization management
- Data involved
- User identity data, authentication identifiers, session metadata and organization membership data where applicable.
- Region
- United States; international transfers may apply
08 — RESPONSIBLE DISCLOSURE
Security issues can be reported directly to Evolize.
If you believe you have identified a security vulnerability affecting Evolize, send a report to the address below. Include the affected service, reproduction steps, potential impact and any relevant evidence.
- Do not access or retain data belonging to other customers.
- Do not perform denial-of-service testing.
- Do not use social engineering.
- Avoid destructive testing.
- Remove sensitive personal data from submitted evidence where possible.
- Allow Evolize reasonable time to investigate before public disclosure.
No monetary bug bounty is currently offered.
09 — DOCUMENTATION