The fine print
What we protect, and how
Last reviewed 10 October 2026
A scanner that browses the sites you point it at is a target in its own right. This page lists the specific protections in place today, and the limits we know about.
Behind-login scans
Scanning behind a login runs through the CLI, on your machine. The CLI saves the signed-in browser session to a local file written with owner-only permissions, and refuses to use a session file that other users on the machine can read. The session is never uploaded to us. The hosted service scans public pages only.
The scanner itself
Every navigation, whether the starting URL, a link a persona follows, or a redirect, is checked before the browser loads it. The check resolves the hostname and refuses loopback, private network, link-local (including the cloud metadata address 169.254.169.254), carrier-grade NAT, and the IPv6 equivalents, including addresses wrapped inside IPv6.
Checking an address and then connecting to it leaves a gap a hostile DNS server can exploit. On the hosted worker, that gap is closed at the network layer: all browser traffic goes through an egress proxy that re-checks every connection as it opens, and the worker refuses to start a browser if that proxy is missing. The option to scan private addresses exists only in the CLI, for testing your own local builds, and the hosted service never enables it.
Your account data
Accounts, projects, and results live in Supabase with row-level security on every table, so the database itself refuses to return one account's rows to another. Persona replay screenshots are stored in a private bucket and served through temporary links. Payments are handled by Stripe; we never see card numbers. The full list of subprocessors, and what each one receives, is in the privacy policy.
Report a vulnerability
Report security problems privately through GitHub private vulnerability reporting, not in a public issue. Personaudit is maintained by one person, so there is no response-time guarantee and no bug bounty, but every report is read and credit is offered in the fix notes. The scope and known limits are in SECURITY.md, and the machine-readable contact is at /.well-known/security.txt.