Transport security
- HTTPS-only across all customer-facing surfaces.
- HSTS, secure cookies, and modern TLS configurations enforced.
Data handling
- Server-side data stored with reputable cloud providers.
- Account data scoped to the authenticated user via row-level access controls.
- Saved lookups (signed-in users) accessible only to the account that created them.
- Aggregate request metrics held in summarised form for operational visibility.
Operational discipline
- Principle-of-least-privilege access for production systems.
- Dependency updates and security advisories monitored continuously.
- Code changes reviewed before deployment.
Reporting a vulnerability
Suspected vulnerabilities can be reported confidentially to support@checkitnowtools.com. Please include a reproduction path and refrain from public disclosure until we have had a reasonable opportunity to investigate.
Last reviewed: June 2026.