Security

Auditing authenticated pages demands a careful data posture.

You audit pages containing your clients' real content. Here is what leaves the browser, what does not, and how the rest is handled.

What never leaves your browser

  • Page content is not captured or transmitted. Audits record rule findings, not the page itself.
  • Text snippets in findings are redacted in the extension before upload, so personal or client data inside an element does not travel with the violation.
  • Your session cookies and credentials are never read or transmitted. The extension audits the rendered page; it does not touch your authentication.

What is stored

  • Audit results: rule identifiers, WCAG criteria, redacted element selectors, and counts.
  • Issue records and their status history per site.
  • Your account details and workspace structure (clients, sites, target WCAG version).

Where it is stored

Customer and audit data are stored and processed in Canada, on managed infrastructure with encryption in transit and at rest.

We use Google Analytics and PostHog, hosted in the United States, solely for website and product analytics to help us improve the customer experience. These analytics services do not store customer audit results or compliance data.

The categories of provider we rely on are listed in the privacy policy, and a specific, up to date subprocessor list is available on request.

Payments

Card details go directly to Stripe and never touch Complaudax servers. See the pricing page for billing terms.

Questions or disclosures

Security questions and vulnerability reports are welcome at [email protected]. For anything else, use the contact page.