Privacy policy

Last updated 18 September 2026 · TekyTec IT Solutions

The short version

We store your email, your scan history, and the domains you monitor. We don't sell data, we don't run advertising trackers, and we don't share anything with third parties except the infrastructure needed to run the service. Email us and we'll delete your account and everything in it.

Who we are

sitesecure.online is operated by TekyTec IT Solutions. For anything in this policy, contact privacy@tekytec.com.

What we collect

When you create an account

When you run a scan

Automatically

If you join the early access list

Your email address, optionally your website, and which plan you were interested in. Used once, to tell you when that plan launches.

What we don't do

Shared reports

When you create a share link, a trimmed snapshot of that scan becomes readable by anyone holding the URL. The snapshot deliberately excludes AI analysis, detected technology versions and CVE matches — a public link should not hand an attacker a shopping list.

Share links expire automatically (30 days by default). Anyone with the link can view it until then, so only share it with people you intend to.

Third parties

WhoWhat they seeWhy
Our hosting providerData stored on the serverRunning the service
Google (if you use Google Sign-In)That you signed inAuthentication
Google FontsYour IP, when fonts loadTypography
Razorpay (if you pay)Payment detailsProcessing payment — we never see or store your card
Our AI provider (when enabled)Anonymised scan findingsGenerating the written analysis

The AI provider receives check names, statuses and category scores. It does not receive your email, your account ID, or any raw content from the scanned site.

How long we keep things

Your rights

You can ask us to show you what we hold, correct it, delete it, or send you a copy. Email privacy@tekytec.com and we'll action it within 30 days. We don't require a reason and we won't try to talk you out of it.

If you're in the EU or UK, our lawful basis is contract performance for account and scan data, and legitimate interest for security logging and abuse prevention.

Security

Passwords are scrypt-hashed. Traffic is HTTPS-only with HSTS. The application enforces a strict Content-Security-Policy, blocks requests to private network ranges, and rate-limits both scanning and authentication. We publish a security.txt so researchers can report issues to us directly.

No system is perfect. If we ever suffer a breach affecting your data, we'll tell you what happened and what to do about it — without waiting to be asked.

Children

This is a tool for website operators. It isn't directed at children and we don't knowingly collect data from anyone under 16.

Changes

If we change this policy materially, we'll email account holders rather than quietly updating the date at the top.

Questions about any of this?

Email privacy@tekytec.com — a person reads it.

Back to the scanner →