Security
Last updated: June 19, 2026
We understand that trust is everything — especially when you're testing a tool that interacts with your website. Here's exactly how HowsMyApp works and what we do to keep your data safe.
What happens when you run a scan
Understanding exactly what HowsMyAppdoes is the foundation of trust. Here's the complete picture:
- You enter your website URL and start a scan.
- HowsMyApp launches an isolated browser instance in our secure cloud environment.
- The browser visits your website and loads pages exactly as a real user would.
- Our testing engine systematically interacts with each page: clicking buttons, testing navigation, checking form validation, verifying layouts, and simulating user flows.
- Results are collected: identified issues, screenshots as evidence, and performance data.
- When complete, you receive a comprehensive report of findings.
Read-only by design
Every scan is completely read-only. HowsMyApp never:
- Modifies your website. We observe behavior, we do not alter content.
- Submits real data. Form testing validates behavior without storing submissions.
- Creates accounts. We do not sign up, register, or create resources on your site.
- Deploys code. We do not inject scripts, modify files, or change configurations.
Credential and data safety
We take a strict approach to sensitive data:
- We never collect passwords. Authentication headers or cookies you configure for private app scanning are encrypted (AES-256-GCM) and used only for the duration of the scan.
- We do not access source code. Our testing is entirely client-side, interacting with your website as a browser would.
- Scan data is isolated. Each scan runs in an isolated environment. Your data is never mixed with other users' data.
Data encryption
- In transit: All data transmitted between your browser and HowsMyApp is encrypted over HTTPS (TLS).
- At rest: Scan data, screenshots, and account information are encrypted at rest (AES-256) by our database and storage providers.
- Database: We use Supabase for data storage, which provides encryption at rest and access controls.
Access controls
Your scan data is private by default. Only you can view your scan reports unless you explicitly enable public sharing. Team features will include granular access controls so you can manage who sees what.
Infrastructure security
- Scans run in isolated browser environments that are torn down after each scan.
- Our infrastructure runs on established cloud providers (such as Supabase) whose platforms maintain SOC 2 compliance.
- Access to production systems is tightly restricted.
- We follow security best practices for authentication, API security, and data handling.
Responsible disclosure
If you discover a security vulnerability in HowsMyApp, we appreciate your help in disclosing it responsibly. Please report it through our contact form and choose the “Security” topic. We'll acknowledge your report as quickly as we can and work to address verified issues promptly.
Questions?
If you have security-related questions or concerns, reach us through our contact form.