Least privilege
OAuth scopes, short-lived sessions, encrypted secrets, and explicit tenant authorization.
ReachPlane treats crawler evidence, credentials, website mutations, and tenant boundaries as production security concerns.
OAuth scopes, short-lived sessions, encrypted secrets, and explicit tenant authorization.
Risk classification, approval policy, canary deployment, public verification, and rollback.
Requests, responses, decisions, deployment identity, and validation artifacts tied to revisions.
Retention limits, export, verified deletion, and no model training without explicit opt-in.
Contract environments for WordPress, Shopify, OAuth, MCP, databases, and real worker processes.
SSRF controls, redirect limits, response caps, private-address blocking, and governed crawler identities.
Only evidence and site data required for the selected operation.
Tenant-scoped storage, encryption, and PII-safe logs.
Raw crawl data for 90 days; reports while subscribed plus six months.
Self-service export, revocation, and verified deletion workflow.
Send a concise reproduction and impact description to security@reachplane.com. Do not include credentials or personal data.
Run a first access check in minutes. Connect your site only when you are ready to repair.