Terms of Use & Privacy
Broid Business Solutions — AI App Security Audit · Last updated 15 August 2026
Authorization required. Only scan websites and applications that you own or are explicitly authorized to test. Scanning systems without permission may be illegal in your jurisdiction. By using this tool you confirm you have that authorization.
1. What the tool does
The Broid Business Solutions — AI App Security Audit performs an automated, external security assessment of a web address you provide — reading publicly observable security headers, checking for exposed files, cookies, transport security, and known dependency vulnerabilities. It is a first-line screening aid, not a penetration test, code review, or guarantee of security.
Broid also performs bounded active checks, and we describe them here so you know exactly what you are consenting to. It extracts the public database key already present in your page and issues read-only, count-only requests to your Supabase or Firebase project to test whether anonymous access is possible; and it sends a single harmless message to up to three AI or chat endpoints on your own domain to test whether they are unauthenticated or unthrottled. It performs no writes, no deletions and no authentication attempts.
2. Acceptable use
- Scan only sites you own or are authorized to assess.
- Do not use the service to attack, overload, or gain unauthorized access to any system.
- Do not attempt to abuse, resell, or automate the service beyond fair personal or business use.
3. No warranty
The service is provided "as is." A passing grade does not guarantee an application is secure; automated external scanning cannot see backend logic or authenticated areas. Broid is not liable for decisions made based on results. For production systems handling real data, obtain a professional security audit.
4. Privacy & data
- We store the URLs you scan, your account identifier, credit balance, scan history, generated reports, and — if you provide it — your email address, in order to operate the service.
- When you connect a GitHub repository or provide a code-audit result, we scan it to produce findings. We do not store your source code; access tokens you provide are used only for that request and are never saved.
- If you contact us through a form on this site, we keep your name, email address and message so we can reply.
- We do not sell your personal data.
- Grades are retained per domain. When a scan completes we keep the resulting letter grade, score and timestamp for the scanned domain — nothing else. No findings, no report contents, no account details and nothing identifying the person who ran the scan are stored against that record or ever shown publicly.
- We do not publish weak grades, and you cannot look one up. A stored grade appears on the public verification page, the partner badge, a shared card or a social image only when it is B or better. Anything below that is treated exactly as though the domain had never been scanned, and we do not distinguish between the two cases — so Broid cannot be used to find out whether somebody else's site is exposed. If your own site scores below B you still receive the complete result, findings and all, in the scan you ran; we simply do not put it anywhere public. This is a deliberate limit on our own product and we will not relax it.
- What we do publish. Two things, and nothing else. First, aggregate statistics across every site scanned — percentages and counts only, never a domain, never a finding (see the dataset). Second, in our own published research and commentary, we may name a major global platform in connection with configuration that anyone can observe in a browser in seconds — for example a missing security header. We do not name a small site or a private business in connection with a weak result, and we never name any site in connection with a weakness that is exploitable. Where we do name a platform, we state the date of the scan so the measurement can be checked or disputed.
- Scan reports reveal weaknesses in the scanned site; handle them confidentially. Reports are private to the account that unlocked them — someone who obtains the link but is not signed in as the owner sees a sign-in prompt, not your report. Reports generated before this control was added remain link-accessible, so treat older links as shareable.
- If you arrived through a Broid partner's referral link or badge, that partner can see the purchases attributed to them, including the email address on the referring account, so they can verify the commission they earned. Partners are contractually bound to keep this confidential and not to use it for anything else (see the Partner Programme terms). If you would rather not be attributed to a partner, contact us and we will remove the attribution.
- You may request access to, correction of, or deletion of your account and associated data by contacting us.
5. Service providers
To operate Broid we rely on trusted third-party processors, each handling only what their function requires: Vercel (hosting), Upstash (database), Clerk (sign-in/identity), Stripe (payments — we never see or store your card details), Resend (transactional email), Anthropic (the AI assistant and code-audit features), OSV.dev (open-source vulnerability lookup — receives the names and versions of libraries detected on your site), and Google Public DNS (DNS-over-HTTPS — receives the domain being scanned, to check its SPF, DMARC, DNSSEC and CAA records). Your use of Broid is also subject to these providers' terms where applicable.
6. Credits, payment & refunds
- Full reports are unlocked using prepaid credits purchased through Stripe. One credit unlocks one full report.
- If a scan fails to complete, the credit is automatically returned.
- Because reports are delivered digitally and instantly, credits are non-refundable once a report has been generated, except where required by law or at our discretion for a genuine service fault.
- Prices and credit-pack contents may change; the price shown at checkout is what applies to that purchase.
7. Cookies & local storage
We use your browser's local storage and cookies for three things, all of them functional:
- Your account — keeping you signed in and remembering your credits and scan history.
- Referral attribution — if you arrive via a partner's link or badge, we store that partner's code in your browser for up to 90 days so the partner is credited if you later buy. It contains no personal data and is not used to build a profile of you.
- Sign-in security, handled by our identity provider (Clerk).
We do not use third-party advertising or tracking cookies, and we do not run cross-site analytics. You can clear this data at any time in your browser settings; clearing it removes any guest credits held only in that browser.
8. Contact
Questions, authorization queries, refund requests, or data requests: broid@broid.net.