Information we collect
When you use Audit My CMS, we may collect the target website URL, normalized host, ownership verification token path, email address, scan status, scan results, scanner diagnostics, HTTP request summaries, report access records, and related timestamps.
If report access is requested, Audit My CMS stores report access status, package type, timestamps, and provider reference IDs needed to unlock report downloads and support access requests.
How we use information
We use scan information to verify ownership, queue and run passive health and security scans, show result pages, generate PDF and DOCX reports, send completion email notifications, diagnose blocked or incomplete scans, prevent abuse, and maintain service reliability.
Scanner traffic may use Audit My CMS infrastructure and selected proxy infrastructure for some passive probes. Target URLs and request metadata may be processed by those systems only as needed to perform the scan.
Third-party services
Audit My CMS may use infrastructure providers for hosting, database, queues, email delivery, report access processing, and logs. Google Safe Browsing may be queried when malware or phishing reputation checks are configured.
Retention
Public result pages and report downloads are available only during the retention period shown on the result page. Administrative records may be retained longer for support, audit history, report access reconciliation, security review, and abuse prevention.
Security and choices
We use access controls, environment-based secrets, and application safeguards to protect scanner and report data. Do not submit a website unless you own it, manage it, or have authorization to request a scan.
To request help with a scan record, report access, or privacy question, use the Contact page.