Home / Security

Security, all the way into this site.

A security vendor that exposed its own users would have no credibility. Here is how we protect your targets, your data — and this site itself.

On your targets

Non-destructive detection.

The scanner proves a flaw without causing harm. It never runs a destructive query, writes nothing, extracts no data by default.

Read-only

Bounded read-only verification. Never DROP/DELETE/UPDATE, never upload or persistence.

Nothing is kept

A finding records a verdict and a benefit category — never the extracted data itself.

Controlled rate

Adjustable rate and aggressiveness. A stealth mode spares fragile targets and WAFs.

Your data on this site

Only what’s strictly necessary.

The signup form only collects what’s needed to reply to you. Full detail in the privacy policy.

Minimisation

Name, email, phone, site to audit, plan. No superfluous data, no ad tracker.

Anonymised IP

Your IP address is never stored in clear — only a truncated fingerprint, useful against abuse, useless to re-identify you.

No resale

Your data is never sold or shared for advertising. Full stop.

This site, put to the test

Hardened as we recommend.

The measures we audit in others, applied here.

0 SQL injection

Every query is prepared and parameterised. No user value is concatenated into SQL.

Anti-XSS

Auto-escaped output + a strict Content-Security-Policy (no third-party inline script).

Anti-CSRF

Signed double-submit token + HttpOnly / SameSite=Strict cookies.

Anti-abuse

Global and form-hardened rate limiting, honeypot and anti-bot timing check.

Hardened headers

HSTS, X-Content-Type-Options, X-Frame-Options DENY, Referrer-Policy no-referrer, Permissions-Policy.

Zero external request

Fonts, styles, scripts and video are self-hosted. No third-party leak, no CDN.

Responsible disclosure

Found a flaw?

We take this site’s security seriously. If you discover a vulnerability, email us at contact@sauronsec.com with a description and, if possible, a proof of concept.

  • We acknowledge within 72 h.
  • Please do not disclose publicly before a fix.
  • No destructive testing, no access to data that isn’t yours.

TO ADJUST indicative timelines and terms.

Security is something you prove.

That’s exactly what our scanner does.

Ready to scan without a shadow of doubt? Request an audit