How we handle security
A security tool should be safe to point at your own website, and careful with what it learns.
How a scan behaves
- Read-only. We look at what any visitor's browser can see: pages, headers and public DNS records. No password guessing, no exploits, nothing that changes your site.
- Only with permission. You confirm you own the website, or are allowed to test it, before every scan.
- Public websites only. The scanner refuses private and internal addresses, so it can't be turned against someone's internal network.
- We don't keep what we find. If a sensitive file is exposed, we record that it exists, never what is inside it.
- Limited. The number of scans one person can run is capped, so the service can't be used to flood a website.
Run a website and saw us in your logs? About our scanner lists exactly what it requests and how to ask us not to scan your domain.
How we protect your account
- Passwords are stored only as a scrambled (hashed) value. We can't read them.
- Sign-in attempts are limited to slow down guessing.
- Password reset links work once and expire after an hour. Using one signs every device out.
- Sign-in tokens from Google and GitHub are stored encrypted.
- The whole site is served over HTTPS, with a strict Content Security Policy and no third-party scripts.
What a score means
Royals Security is an assessment, not a guarantee. A high score means we didn't find the common problems we check for. It doesn't mean a website can't be attacked.
Report a security problem
If you think you've found a security problem with Royals Security itself, please tell us before making it public so we can fix it. Use the contact form and choose "Report a security problem". Include what you found and how to reproduce it. We'll reply as soon as we can.
Please don't access other people's data, or run tests that could disrupt the service, while looking.