Where your data goes
Two different things happen on this site, and they deserve two different answers. The scans look at a domain from the outside, the way anyone on the internet can — so the domain name has to leave your browser, because there is no other way to read a certificate or find an open port. The questionnaires ask about how you run your business, and those answers never leave the tab at all. There is no account, no email field and no sign-up anywhere in the free tools.
None of that is a policy you have to believe. Below is exactly where the line sits, and four ways to check it without asking us.
The line we draw
Leaves your browser
- The domain you ask us to scan. A public business identifier — it is already in DNS, on your website and in the headers of every email you send.
- Your answers, once, if you ask for a PDF. Named below rather than buried.
- Proof you control the domain, for an in-depth scan only — a file you upload to your own web root, or a DNS record you publish.
Never leaves it
- Your questionnaire answers, on all five readiness checks — what you patch, who has MFA, whether a director is disqualified, what your insurer was told.
- Who you are. No account, no email, no password, no name field. We could not build a profile of you if we wanted to, because there is no key to hang one on.
- Any history. Nothing from a free tool is written down — not the scan, not the result, not the report.
What happens to what you type
The readiness checks — Cyber Essentials, UK GDPR, cyber insurance, fundraising tech DD, public-contract eligibility — ask you to admit things. Whether you actually patch inside fourteen days. Whether every account really has MFA. That is an uncomfortable list to type into a stranger's website, so the product is shaped around it.
- 01The questionnaires are scored in your browser. The questions, the contradiction engine, the auto-fail rules and the verdict are all code running on your machine. Producing the report on screen involves no request to us at all.
- 02The one time your answers leave is the PDF — and we say so. A PDF has to be typeset somewhere, and ours is typeset on the server. So pressing Download PDF sends your answers and your report once. They are rendered and handed straight back in the same request: nothing is written to a database, nothing is logged, nothing is counted against you. If you would rather that never happened, the report on screen is complete without it — print the page instead.
- 03The scan cross-check sends a domain, never your answers. The thing that makes these checks worth running is that we compare what you claimed against what a scan can actually see. That comparison happens in the tab: we fetch observations about a domain, and your answers meet them on your machine. The request carries
?domain=and nothing else — it is a GET, it has no body, and there is nowhere in it for an answer to travel. - 04The scans run on our server, because they cannot run anywhere else. A browser cannot open a TCP connection to port 3306, read a certificate chain, or resolve a DMARC record — those abilities are deliberately withheld from web pages. Every scan we run therefore runs from our infrastructure, and what it examines is what your domain already publishes to anyone who asks for it.
- 05No cookie identifies you. Three exist —
grc_post,grc_expandgrc_link— and each holds two numbers: how many times this browser has used that one tool, and when the day started. No identifier, nothing to join up, and clearing them resets the count. They exist because the reputation providers give us a shared daily allowance and one looping browser would spend everyone's. - 06Nothing from a free tool is stored. The posture scan, exposure check, link checker, email-spoofing check and all five readiness reports write nothing down. Close the tab and the result is gone — from us, and from your machine.
Who else sees anything
A scan is partly a matter of asking other registers what they already know about a domain, so some of what you type reaches somebody else. Here is the complete list, what goes, and when. Nothing on it is triggered by the questionnaires.
Google Public DNS
The domain name
Posture scan — the DNSSEC check, which an ordinary resolver cannot answer.
VirusTotal · AbuseIPDB · URLhaus · Google Safe Browsing
The domain, or its IP address. On the link checker, the URL you pasted
Posture scan (reputation) and the link checker. Each provider is optional and is skipped entirely if we have not configured a key for it.
Companies House
The company number you picked from the list
Public-contract eligibility check — the register lookup is the check. We never send a company name we guessed at.
Stripe
Your card details, which go to Stripe and never to us
The in-depth scan, if you buy one. Guest checkout, so no customer account is created to be retained.
The in-depth scan is the one thing we keep — and it deletes itself
The paid scan takes many minutes and runs on a worker outside the website, so its results have to be written down somewhere between starting it and you coming back to read it. That is the only part of the platform with a database row in it, so it is worth being precise about.
- Still no account. You prove you control the domain, pay once as a guest, and get a secret link. The link is the key — we store only a hash of it, the way a password is stored, so we cannot reconstruct it.
- It is deleted after about three days, by a scheduled job that runs whether or not anyone remembers to press anything. Not a promise to tidy up later — a cron entry.
- Lose the link and we genuinely cannot help you. There is no email address to send it to and nothing tying the scan to you, so recovery is impossible by construction. That is the cost of the design, and we would rather say it here than in a support reply.
How to check all of that without asking us
A claim of this kind is worth what it can be tested against. Four tests, in increasing order of thoroughness. The first two need nothing from us.
- 1
Answer a questionnaire with the internet switched off.
Open the Cyber Essentials check, let it load, then turn on airplane mode and answer all fourteen questions. The verdict, the auto-fail logic and the remediation list all still appear, because that code is running on your machine. Something that scores your answers with the network off is not sending them anywhere. It takes a minute.
- 2
Watch the network tab.
Your own IT team can open the browser developer tools and see every outbound request the page makes, live. Fill the questionnaire in front of them: nothing leaves until you ask for one of two things — the scan cross-check, which carries a domain, or the PDF.
- 3
Read the response headers.
curl -I https://grc-scan.comprints an enforced Content-Security-Policy. Itsconnect-srcis this site and our database, and nothing else — so your browser is not permitted to contact any of the third parties above, even if our code tried. Your browser enforces that, not us.Being straight about the limit of that test: it proves where your browser may go. It says nothing about what our server does on your behalf — for that, the table above and the methodology page are the honest answer. - 4
Ask us to put it in writing.
We will give a written confirmation of non-retention as an annex to an NDA, and we will walk your security team through any check on this page on a call, against a domain you choose.
The principle underneath
For everything except the paid scan, we do not hold your data — not because we have undertaken not to, but because there is nowhere to put it. No account, no email field, no identifier: nothing to attach a history to. The useful consequence is that we never become a processor of your data at all, so there is no data-processing agreement to negotiate and nothing about our internal procedures you have to take on trust.
Where we do hold something — the in-depth scan — the same principle is enforced differently: by a deletion that is scheduled rather than remembered.
“We are not allowed to” is a promise. “There is nowhere to” is a fact — and one you can confirm in two minutes.
The one thing we will not pretend
Typing your own domain into a scanner does tell us something about you, in the moment you do it. It is the input; there is no version of this product where it is not. We are not going to claim otherwise, because your security team would spot it immediately and then doubt everything else on this page.
What is true is narrower and more useful: we do not keep it, we do not join it to anything, and we do not know who typed it. A domain arrives, a scan runs, a result goes back, and the only trace left is a counter that reads 2026-09-08 · posture_scan · 14 — a date, an action and a number, with no domain in it and no person behind it.
It is also worth saying that the alternative is usually less private, not more. Checking your own exposure by hand means pasting your domain into whichever free port scanner comes up first, which is an outbound request carrying the same identifier to somebody who does keep a history, build a profile and sell a report about it.
Full disclosure
The things we collect that are not part of any scan. We mention them unprompted because the alternative is your security team finding them after we said we collect nothing, and that costs more than the facts themselves are worth.
- Cookieless traffic analytics — page, country, referrer. No cookie, no identifier, nothing joining one visit to the next. Form contents are not collected and could not be: they never reach a server.
- Aggregate counters — a date, an action name and a number, so we know whether anyone is using the thing we just built. There is no domain, no IP address and no visitor in them, and they cannot be turned back into either.
- Ordinary server logs — our host keeps request logs, as every host does. We do not mine them and they age out on the host's own schedule, not ours.
- Where it all runs — the website on Vercel, the small amount of scan state in a managed Postgres database, and the in-depth scanner on a machine we run ourselves. Payments go to Stripe and card details never touch our servers.
The formal version of all of this, written for the UK GDPR transparency requirement, is the privacy notice. This page and that one describe the same system; if you ever find them disagreeing, tell us — that is a bug, and the sort we would want to hear about.