passive security & quality audit for sites built with ai
← back to the toolLast updated: September 2026. Plat.one is operated by Semalt LP — see About for company details.
The URL you submit — stored so your report page
stays reachable at its private link later.
The scan findings we generate — headers, TLS
status, matched patterns, etc. Any secret-looking string we detect is stored and shown
masked (first/last few characters only), never in full.
Standard web server logs — IP address, user agent,
and request time for requests to Plat.one itself, kept for abuse prevention and debugging.
We do not link these logs to individual scan records.
No accounts, no cookies, no analytics trackers, no ad pixels on Plat.one. We don't sell or share scan data with third parties, except as needed to run a check you asked for — the JS library versions we detect are sent to OSV.dev's public API to check for known vulnerabilities; nothing else about your scan is sent anywhere else.
Each report lives at an unguessable, randomly generated address (not a sequential number) and
is marked noindex so search engines don't index it. We don't list scanned URLs or
report links anywhere on the site — only someone with the exact link can open a report. Still,
treat the link itself as sensitive if the findings would be: anyone who has it can view the
report.
Contact us via the details on our About page to request a report be taken down, or to ask what data we hold about a scan. We'll act on removal requests promptly.