Our own security
The rule we hold ourselves to: KeptShut never runs an active check against a hostname the customer has not proven they control.
Ownership before probing
Every deep check passes through one authorisation helper. It checks the plan and it checks the proof of ownership. A refusal is written to an audit log, so a denial leaves evidence rather than silence.
Credentials
Provider credentials are encrypted at rest with libsodium and requested with the narrowest scope that does the job. Automatic key revocation only happens when you have switched it on for that connection.
Takedowns
Clone and impersonation reports are drafted for you and sent through documented abuse channels. KeptShut never sends one by itself.
Reporting a problem
Email security@keptshut.com. We answer within two business days and we will not threaten you for a good-faith report.
Questions
Do you scan domains I have not proven I own?
Only with checks a normal visitor could run themselves. Anything active, authenticated or probing requires proof of ownership first.
Where are my provider credentials stored?
Encrypted at rest with libsodium, with least-privilege scopes, and only when you explicitly connect a provider. Revoking a key is never automatic unless you pre-authorise it.
How do I report a vulnerability in KeptShut?
Email security@keptshut.com. We will confirm within two business days. There is a security.txt at /.well-known/security.txt.