Security boundaries you can verify.
Security overview and responsible-disclosure instructions for the public scanner and pre-release read-only platform connections.
Scope at a glance
The public scanner performs a bounded read-only crawl. Pre-release Zendesk and Gorgias connections use platform OAuth and least-privilege read scopes; neither mode writes to source content.
Current product boundary
CheckMyHelpCenter offers an anonymous public-content scanner and contains pre-release Zendesk and Gorgias OAuth flows. Platform OAuth is the only connected sign-in mechanism; there is no separate ChatGPT or DocSanity password login. The connections remain unavailable to customers until credentials, marketplace review, and listed release gates are complete. No Shopify OAuth flow is implemented.
The public scan is designed to be read-only. It fetches pages available without authentication and never submits a source edit, publishes an article, changes a macro, or acts as a support agent.
Controls used by the public scanner
The production service uses HTTPS and Cloudflare's delivery and security infrastructure. Application safeguards include URL and protocol validation, blocks for obvious local and reserved destinations, redirect checks, bounded page discovery, request and response size limits, scan timeouts, and no-store responses for audit reports.
These controls reduce risk; they do not make automated crawling infallible. The methodology page documents coverage and network-validation limitations. We do not claim a security certification, formal penetration test, or public bug-bounty program that has not been completed.
Data handling and access
Raw public article text is processed transiently and is not intentionally kept in an application report database after the scan response. Standard Cloudflare operational logs and Google Analytics usage data are separate processing described in the Privacy Policy.
The public scanner cannot read private sources. Pre-release connected mode is limited to Zendesk Guide articles and Macros or Gorgias Macros. It does not request tickets, customers, attachments, write permissions, or support conversations. Never send credentials, OAuth tokens, private URLs, or customer data to the public scan form or a support email.
Connected integration controls
Implemented controls include HMAC-bound, single-use 10-minute OAuth state, callback and start rate limits, Zendesk PKCE, protected platform API checks of the approved account and current administrator, fixed platform API hosts, bounded responses and retries, encrypted token storage, refresh-token rotation locks, installation-qualified sessions and queries, same-origin checks on mutations, short-lived signed Zendesk embed requests, read-only scopes, scan rate limits and leases, audit events, a retryable encrypted revocation queue, daily retention maintenance, disconnect, and tenant deletion. Gorgias receives an OAuth nonce, but authorization decisions rely on the protected Account and current-user API responses rather than unverified ID-token claims.
Connected scans run only when an administrator requests one. No scheduler, polling job, webhook ingestion, background sync, or write-back path is enabled in this release. The public site remains non-embeddable; only signed Zendesk app routes receive a narrow zendesk.com frame policy. Production secrets, platform sandbox end-to-end tests, alerting, and legal review remain activation gates, and no independent certification or penetration-test claim is made.
Responsible disclosure: report a security issue
Email support@willgo.tech with the subject “Security report.” Include the affected URL or component, clear reproduction steps, likely impact, and a safe proof of concept. Do not include credentials, customer data, or destructive test results in the first message.
Please act in good faith: avoid privacy violations, data destruction, service disruption, persistence, social engineering, and testing against third-party Help Centers without permission. We will acknowledge and triage reports as practicable, but no fixed response-time SLA or monetary reward is currently promised.
Security questions
For security questionnaires, marketplace review questions, or vulnerability coordination, contact support@willgo.tech. Please identify whether the question concerns the anonymous public scanner or the pre-release connected product.