PRODINT

Trust

Security

What we do to protect your account, your research and any logins you hand the crawler.

Last updated 25 September 2026

Your account

  • Passwords are stored as bcrypt hashes. We never see or store them in plain text.
  • Sign-in and sign-up are rate limited to slow down password guessing.
  • Your session lives in a signed, HTTP-only cookie that page scripts can't read.
  • API tokens are per user, and you can replace yours at any time from your account page.

Logins you give the crawler

When a crawl reaches a login, you sign in yourself, on the site's own login page, in a browser streamed to the Needs you page. Your clicks and keystrokes are relayed to that browser: they're kept out of our request logs, held for at most a minute while they're replayed, and never saved. Once you're in, Prodint keeps the browser's session (cookies and local storage), not your password, so the crawl can continue:

  • Saved sessions are encrypted at rest.
  • They expire after 14 days, and a crawl that needs one after that asks you again.
  • They're used only for crawls of the source you signed in to, in your workspace.

Use an account you're entitled to use for this, and we suggest a dedicated one rather than someone's personal login.

Your workspace data

  • Dossiers, product maps, crawled pages and screenshots belong to a workspace, and only its members can see them.
  • Your research isn't shown to other customers or used to build anyone else's product map.
  • Card payments are handled by Stripe. Card numbers never reach our servers.

AI processing

Page text and reviews are sent to Anthropic's AI models, either directly or through OpenRouter, to extract features and summarise reviews. See the privacy policy for the full list of services that process data for us.

The crawler

The crawler never submits forms, skips state-changing paths such as logout, delete and checkout, and refuses to fetch private network addresses, so a crawl can't be pointed at internal systems. More on the page for site owners.

Reporting a vulnerability

If you think you've found a security problem, email [email protected] with the details and steps to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and don't access other people's data or disrupt the service while testing. We'll reply, keep you posted, and credit you if you'd like.