Security and trust

Automation that can prove what it did and undo it.

ReachPlane treats crawler evidence, credentials, website mutations, and tenant boundaries as production security concerns.

Core guarantees

Designed to reduce both access risk and automation risk.

Least privilege

OAuth scopes, short-lived sessions, encrypted secrets, and explicit tenant authorization.

Safe mutation

Risk classification, approval policy, canary deployment, public verification, and rollback.

Durable evidence

Requests, responses, decisions, deployment identity, and validation artifacts tied to revisions.

Controlled data

Retention limits, export, verified deletion, and no model training without explicit opt-in.

Reproducible validation

Contract environments for WordPress, Shopify, OAuth, MCP, databases, and real worker processes.

Network safety

SSRF controls, redirect limits, response caps, private-address blocking, and governed crawler identities.

Data lifecycle

Useful long enough. Never indefinite by default.

01Collect

Only evidence and site data required for the selected operation.

02Protect

Tenant-scoped storage, encryption, and PII-safe logs.

03Retain

Raw crawl data for 90 days; reports while subscribed plus six months.

04Delete

Self-service export, revocation, and verified deletion workflow.

Responsible disclosure

Found a security issue?

Send a concise reproduction and impact description to security@reachplane.com. Do not include credentials or personal data.

Contact security
Ready for the agentic web

Let every useful agent in.
Keep every risky change governed.

Run a first access check in minutes. Connect your site only when you are ready to repair.