What the scanner does โ and never does
- Fetches only publicly reachable pages, stylesheets, and documents โ the same requests any visitor's browser makes.
- Identifies itself honestly with the
AccessHawkBot/2.0user agent and a link to this site. - Read-only, always: it never logs in, never submits forms, never attempts authentication, never probes for vulnerabilities, never executes site code.
- Strictly capped: at most 30 HTML pages, 3 stylesheets, and 10 PDFs per scan, with per-request timeouts. Private/internal addresses are refused at the API layer.
Infrastructure
- AccessHawk runs entirely on Cloudflare's edge network (Workers/Pages) โ no servers of ours to patch, no database ports exposed. Cloudflare maintains SOC 2 Type II, ISO 27001, and FedRAMP-authorized services; details at cloudflare.com/trust-hub.
- All traffic is TLS-encrypted in transit. Stored data (saved reports, email addresses) lives in Cloudflare's storage, encrypted at rest.
- Minimal data by design: no accounts, no passwords, and no personal data beyond an email address you choose to provide. Shared reports auto-expire after 180 days.
For government purchasers
- The Service touches only your public website content โ no PII, CJIS, HIPAA, or tax data ever enters the system, which keeps data-classification review simple.
- Data residency: Cloudflare is a U.S. company; storage for this service is configured in Cloudflare's standard (U.S.-inclusive) regions.
- Security questionnaires, our W-9, and insurance certificates are available on request as part of procurement โ see the capability statement.
Vulnerability reports
Found something? Email [email protected] with "security" in the subject. We commit to acknowledging reports within 2 business days and won't pursue good-faith researchers.
Last updated July 22, 2026.