KeptShut

Our own security

The rule we hold ourselves to: KeptShut never runs an active check against a hostname the customer has not proven they control.

Ownership before probing

Every deep check passes through one authorisation helper. It checks the plan and it checks the proof of ownership. A refusal is written to an audit log, so a denial leaves evidence rather than silence.

Credentials

Provider credentials are encrypted at rest with libsodium and requested with the narrowest scope that does the job. Automatic key revocation only happens when you have switched it on for that connection.

Takedowns

Clone and impersonation reports are drafted for you and sent through documented abuse channels. KeptShut never sends one by itself.

Reporting a problem

Email security@keptshut.com. We answer within two business days and we will not threaten you for a good-faith report.

Questions

Do you scan domains I have not proven I own?

Only with checks a normal visitor could run themselves. Anything active, authenticated or probing requires proof of ownership first.

Where are my provider credentials stored?

Encrypted at rest with libsodium, with least-privilege scopes, and only when you explicitly connect a provider. Revoking a key is never automatic unless you pre-authorise it.

How do I report a vulnerability in KeptShut?

Email security@keptshut.com. We will confirm within two business days. There is a security.txt at /.well-known/security.txt.