Security

Auditing authenticated pages demands a careful data posture.

You audit pages containing your clients' real content. Here is what leaves the browser, what does not, and how the rest is handled.

What never leaves your browser

  • Page content is not captured or transmitted. Audits record rule findings, not the page itself.
  • Text snippets in findings are redacted in the extension before upload, so personal or client data inside an element does not travel with the violation.
  • Your session cookies and credentials are never read or transmitted. The extension audits the rendered page; it does not touch your authentication.

What is stored

  • Audit results: rule identifiers, WCAG criteria, redacted element selectors, and counts.
  • Issue records and their status history per site.
  • Your account details and workspace structure (clients, sites, target WCAG version).

Where it is stored

Application data is hosted on managed infrastructure with encryption in transit and at rest.A detailed subprocessor list and hosting region statement is being finalized and will be published on this page.

Payments

Card details go directly to Stripe and never touch Complaudax servers. See the pricing page for billing terms.

Questions or disclosures

Security questions and vulnerability reports are welcome at [email protected]. For anything else, use the contact page.