Account and data isolation
Authentication is provided by Supabase Auth. PostgreSQL Row Level Security policies restrict projects, URLs, snapshots and regressions to the account that owns them. Private server credentials are kept out of browser code.
Safe URL fetching
The crawler accepts HTTP and HTTPS URLs only. It rejects credential-containing URLs, localhost, private and reserved IP ranges, cloud metadata targets and unsafe redirect destinations. It limits redirects, response size, timeout, concurrency and per-account usage.
Data minimization
Snapshots store normalized SEO signals instead of complete HTML pages. Application logs are designed to exclude passwords, authentication tokens, service credentials and unnecessary response headers.
Platform controls
The application uses encrypted HTTPS transport, security response headers, Netlify’s managed application platform and Supabase database controls. Dependencies and application changes are checked before deployment.
Responsible disclosure
If you believe you found a security issue, email support@seoregressionmonitor.com with a clear description. Do not access other users’ data, disrupt service or publicly disclose an unaddressed issue.
Current beta limits
Domain verification, scheduled monitoring and transactional regression email are staged features and may remain disabled until their production controls are verified. Each project displays its current monitoring status.