30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.
| ID | Check | Passes when |
|---|---|---|
| 7.7.01 | Detect exposed emails in URLs | None |
| 7.7.02 | Detect exposed phone numbers in URLs | None |
| 7.7.03 | Detect exposed user IDs in query params | None |
| 7.7.04 | Validate PII classifier scans HTML output | Scanned |
| 7.7.05 | Validate PII classifier scans JS-rendered output | Scanned |
| 7.7.06 | Detect PII in server error messages | None |
| 7.7.07 | Detect PII inside JSON payloads or API responses | None |
| 7.7.08 | Detect PII in metadata (meta tags / OpenGraph) | None |
| 7.7.09 | Validate PII not included in structured data | None |
| 7.7.10 | Compute PII Discovery Exposure Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.7.11 | Validate passwords hashed with modern algorithm | Hashed |
| 7.7.12 | Validate encrypted fields (emails, phones) | Encrypted |
| 7.7.13 | Validate access logs recorded for sensitive data | Recorded |
| 7.7.14 | Validate encryption keys rotated | Rotated |
| 7.7.15 | Validate API tokens not storing PII in payload | Clean |
| 7.7.16 | Detect unencrypted backups | None |
| 7.7.17 | Validate PII redaction for logs | Redacted |
| 7.7.18 | Validate PII masked on admin panels | Masked |
| 7.7.19 | Detect dev tools that leak PII | None |
| 7.7.20 | Compute PII Storage & Encryption Compliance Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.7.21 | Validate GDPR/CCPA request workflow functional | Functional |
| 7.7.22 | Validate user data deletion works | Works |
| 7.7.23 | Validate data export functionality | Exportable |
| 7.7.24 | Validate consent banners collected + logged | Logged |
| 7.7.25 | Validate opt-out mechanisms present | Present |
| 7.7.26 | Validate PII sharing with third parties documented | Documented |
| 7.7.27 | Detect undeclared data brokers receiving data | None |
| 7.7.28 | Validate role-based access controls enforced | Enforced |
| 7.7.29 | Validate session timeouts for PII access | Timed |
| 7.7.30 | Compute PII User Access & Regulatory Compliance Score | Finalized |
← 7.6 Bot Mitigation & AI/Bot Access Control7.8 Cache Poisoning Defense →
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plansMachine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).