Boundary
Trust
No compliance badge is claimed. Public fetch stays on one side. Account data stays on the other.
- Public website
- Safe bounded fetch
- Readiness report
- Account data
- Authenticated workspace
- Tenant boundary
- Owner control
Public vs private
Marketing pages may be indexed. Readiness reports for an anonymous scan are not. Workspace and admin pages require a session. The free scan fetches public pages and does not ask for credentials to the target site.
Safe crawling
Private and internal addresses are refused. Credentials in the submitted address are rejected. The crawl is bounded in pages, bytes, and time.
Tenant isolation
Account records stay separated by merchant. A scan of a public URL does not become a tenant record by itself.
Publication control
Publication is opt-in and is not performed by the scan.
Authentication
Workspace sign-in uses a host-only session cookie. Customer checkout is not taken on this origin.
MFA
The owner admin path uses MFA. A readiness report does not bypass that step.
Email security
Product mail is sent as AXIORA AI. Support, security, and privacy mailboxes are separate aliases. This site is served over HTTPS.
Report privacy
A report stores the evidence the fetch observed. It is not a public directory listing, and anonymous reports are not indexed.
Data retention
The stored report remains available at its report address so the same scan can be reopened. It is not published as a listing.
Responsible scanning
The fetch stays on the public site that was submitted, within the page, byte, and time budget. It does not guess hidden pages.
Security reports go to security@axioraworld.com or the contact page.