Security one-pager
For your security team: what our scanner touches, what we store, and how to switch us off.
Last updated 28 September 2026.
What the scanner does
Read-only. A headless Chromium visits the public pages the crawl finds from your homepage, and the areas behind sign-in that you tick on the Scope page. It follows links, presses Tab, and replays the journeys you import. It submits no forms except the sign-in form, with the test account you gave us, and the steps of your recorded journeys.
Rate-limited and identified. Every request carries the user agent VariantlyScanner/0.1 (+https://variantly.app/security; read-only, rate-limited), which links to this page. If your bot protection challenges us, the scan stops and says so, and nothing is charged for a blocked attempt. Allow-listing our scanner or giving us a test account resolves it.
The test account
Give us a non-production or seeded account with the least access that still shows the product. Its password is sealed with AES-256-GCM under a key held only by the worker process, is never displayed to anyone, and is used only to sign in for a scan. Revoke our access by deleting the account, or by removing it on the Scope page; the sealed credential is deleted with it.
What we store
Captures of your product's pages: screenshots, accessibility trees, screen-reader transcripts, focus traces, rule output, and short videos of journey replays, stored by content hash in private object storage. Captures that a published report rests on are copied to a kept bucket and stay for the life of that version. We store nothing about your customers, because we never scan behind their accounts.
Account and billing records in Postgres. Card details go to Stripe and never reach us.
Where it runs
The web app, the worker with its browser, Postgres, object storage and email each run with a managed provider. The AI tier is Anthropic, which receives captured page evidence for the rows it proposes and never the test account. The current providers, their regions and the scanner's address range for allow-listing are available from security@variantly.app, and are listed here when they change.
Access, transport and retention
TLS everywhere. Secrets live in the host's secret store, and the single sealed-secret key is rotated on request. Access to production is limited to the founders and logged. Nightly captures that no report rests on are deleted after ninety days; everything else follows the privacy policy. Deletion on request within thirty days.
Incidents and contact
Report a vulnerability or an incident to security@variantly.app. We acknowledge within one business day, and we tell affected customers of a confirmed breach without undue delay, and within seventy-two hours where the GDPR applies.
For anything else, write to hello@variantly.app. We reply within one business day. Requests to delete or export your data go to privacy@variantly.app, as the privacy policy says, and are answered within thirty days.