SECURITY & DATA HANDLING

Security begins with limited access.

Evolize analyzes publicly accessible website surfaces without requiring source-code access, production credentials, installed agents or authentication bypass.

Last reviewed:

  • Public surfaces only
  • No credentials
  • No installed agent
  • No authentication bypass

The scanner is designed around a restricted access boundary.

Evolize evaluates the same public pages that customers, automated claim-generation systems and external reviewers can inspect. It does not require privileged access to internal systems.

Evolize may access

  • Publicly reachable webpages
  • Public page assets and browser responses
  • Browser-rendered page output
  • Publicly exposed technical metadata
  • Public accessibility and interaction states
  • Publicly observable responsive behaviour

Evolize does not require

  • Source-code repositories
  • Production or administrator credentials
  • Customer databases
  • Private network access
  • Installed JavaScript or site agents
  • Access to authenticated customer areas

Public-surface scanning is bounded and non-invasive.

Evolize inspects externally observable website behaviour without attempting to exploit, alter or gain privileged access to the target environment.

  • Scans stay within the configured public-page scope.
  • Request concurrency is controlled to limit load.
  • The scanner does not guess or test passwords.
  • The scanner does not attempt to bypass authentication.
  • The scanner does not exploit detected vulnerabilities.
  • The scanner does not complete purchases or irreversible transactions.
  • The scanner avoids state-changing form submissions.
  • Authenticated and private-environment scanning is not supported.
  • Website owners can report unexpected scan behaviour.

Data is collected only where required to detect, reproduce and manage findings.

Each category below is processed for a specific operational reason. Example data is separated from the purpose it serves.

Scan data

Includes

  • Submitted domain
  • Public URLs inspected
  • Browser and response metadata
  • Page structure and rendered output
  • Detected findings and severity
  • Scan timestamps and scan status

Purpose

Used to perform the scan, determine scope and produce findings.

Evidence data

Includes

  • Relevant screenshots or screenshot crops
  • DOM or HTML fragments
  • Stable selectors
  • Accessibility-tree extracts
  • Component fingerprints
  • Responsive-state evidence
  • Finding history and verification records

Purpose

Used to reproduce findings, support remediation and determine whether an issue has changed or returned.

Account and operational data

Includes

  • User and organization details
  • Authentication and session records
  • Subscription and billing metadata
  • Support communications
  • Service logs
  • Security and operational events

Purpose

Used to provide, secure, support and administer the Evolize service.

Evidence follows a defined operational lifecycle.

From the submitted domain to retention or deletion, evidence moves through a fixed sequence of stages.

  1. Domain submitted

    The customer provides a domain or public URL for analysis.

  2. Public pages retrieved

    Evolize loads the permitted public pages within the configured scan scope.

  3. Technical analysis

    The scanner evaluates rendered output, accessibility states, responsive behaviour and other supported rules.

  4. Evidence created

    Relevant technical fragments and visual evidence are stored to support reproduction and remediation.

  5. Retained or deleted

    Evidence is retained according to the applicable plan and deletion policy, then removed when no longer required.

Retention rules are explicit and predictable.

Evolize retains scan evidence only for the period required to provide historical comparison, remediation verification and recurrence detection.

Data retention by category
Data categoryDefault retention
Customer-visible scan history12-month history on Single Website and Portfolio; custom on Enterprise

Customer-visible scan history

Default retention
12-month history on Single Website and Portfolio; custom on Enterprise

Backup deletion. When evidence is deleted, residual copies may remain in routine backups until they age out of the backup rotation. Backup copies are used only for disaster recovery and are not restored into active customer use.

Aggregated metrics. Anonymized or aggregated operational metrics that no longer identify a customer or website may be retained after deletion or account closure, and are used only to operate and improve the service.

Safeguards are listed only when they are operationally verified.

The controls below are implemented today. Additional safeguards are added to this list only after they are in place and confirmed — not in advance.

Transport

Encrypted transport

Connections to Evolize are served exclusively over HTTPS using modern TLS.

Environments

Environment separation

Production, preview and development are configured and deployed separately.

Scan scope

Restricted scan scope

Scanning is limited to configured, publicly accessible website surfaces and does not require privileged system access.

Data

Data minimization

Evolize limits collected and retained data to information required to provide, secure and operate the service.

Service providers are disclosed by function and data involvement.

Evolize relies on the providers below to operate the service. This list is updated when the set of providers changes.

Evolize subprocessors by function and data involvement
ProviderService functionData involvedRegionDocumentation
CloudflareHosting, edge delivery, browser rendering, processing and storageScan inputs, generated evidence and operational metadataGlobal infrastructure; storage and processing locations depend on the configured Cloudflare services and account settingsSecurity documentation (opens in a new tab)
WorkOS, Inc.Authentication, identity and organization managementUser identity data, authentication identifiers, session metadata and organization membership data where applicable.United States; international transfers may applySecurity and privacy documentation (opens in a new tab)

Cloudflare

Service function
Hosting, edge delivery, browser rendering, processing and storage
Data involved
Scan inputs, generated evidence and operational metadata
Region
Global infrastructure; storage and processing locations depend on the configured Cloudflare services and account settings

WorkOS, Inc.

Service function
Authentication, identity and organization management
Data involved
User identity data, authentication identifiers, session metadata and organization membership data where applicable.
Region
United States; international transfers may apply

Security issues can be reported directly to Evolize.

If you believe you have identified a security vulnerability affecting Evolize, send a report to the address below. Include the affected service, reproduction steps, potential impact and any relevant evidence.

security@evolize.com

  • Do not access or retain data belonging to other customers.
  • Do not perform denial-of-service testing.
  • Do not use social engineering.
  • Avoid destructive testing.
  • Remove sensitive personal data from submitted evidence where possible.
  • Allow Evolize reasonable time to investigate before public disclosure.

No monetary bug bounty is currently offered.

Inspect the public surface before someone else does.