Trust
Security & Disclaimers
This page is maintained by the operator to answer common security and operational questions about the Execution Risk Scanner.
Section
What this tool is
The Execution Risk Scanner is a self-assessment diagnostic. It asks you 20 structured questions about your product, applies a deterministic rules-based scoring engine, and returns an opinionated execution-risk report. It does not perform automated penetration tests, code audits, legal reviews, or compliance attestations.
The output is only as accurate as the inputs you provide. The scanner cannot verify facts it was not told. Scores reflect the quality and completeness of your written answers, not ground truth about your product, infrastructure, or legal exposure.
Section
What this tool is not
This is not a security audit, penetration test, legal opinion, compliance attestation, financial advisory service, or technical due-diligence report. Do not use it as a substitute for professional review by qualified security, legal, or compliance personnel.
A high score does not guarantee safe shipping. A low score does not guarantee failure. The report is a structured starting point for conversation, not a final authority on readiness.
Section
Data handling
Signed-out users: scans are stored only in this browser's localStorage under the key ers.scans.v1. Nothing leaves your device unless you sign in.
Signed-in users: scans are stored on our managed backend and bound to your account. Row-level security ensures only you can read or modify your records, unless you explicitly mark a report as shared, in which case anyone with the report URL can read that single record.
We do not sell your data, run advertising trackers, share scans with third parties, or train models on your inputs.
Section
Authentication and access
Accounts are protected by email/password or Google OAuth through our managed identity provider. Passwords are hashed by the provider; we do not store them in plain text.
You can export every scan tied to your account as JSON and permanently delete your scans from the account menu. Shared reports remain accessible to anyone with the link until you disable sharing.
Section
Partner references
The Execution Risk Scanner is powered by Raptor Labs.
Security posture and operations are supported by CyberLink Security.
These references describe operational relationships and do not constitute a certification, endorsement, or guarantee by either party.
Section
Platform and hosting
The application is built on Lovable and hosted through Lovable's managed infrastructure. Backend data is stored in a Lovable-managed database with row-level security enabled on user-facing tables. Payment processing is handled by Stripe.
Platform security is a shared responsibility: Lovable manages the underlying infrastructure, while the operator configures access controls, payment flows, and application-level behavior.
Section
Vulnerability reporting
If you discover a security issue in the application, contact the operator at the support address listed on this deployment. Please provide enough detail to reproduce the issue and a safe way to respond.
Section
Acceptable use
Run scans only on products you operate or are authorised to assess. Do not submit third-party confidential information without permission. Do not enter personally identifying information about your users into the free-text fields; the form stores your inputs verbatim.
