What's true, what's in build, what we don't have yet.
We're a small company, early in our life. You won't find a badge wall here, because we haven't earned the badges yet. What you'll find instead is a precise account of how Correctest handles your application and its data — kept current, stated plainly.

What we touch, where it lives, what reaches the AI
- Your application's pages, forms, and flows — as rendered
- Test-account credentials you provide (encrypted, masked)
- Docs you choose to upload for conformance checking
- Scan video recordings — only if you switch recording on for an application: short clips of what the browser did, kept for about a month after the scan, then deleted
Not your production database. Not your source code. Not your users' data.
Cloudflare R2 (screenshots, recordings, generated projects) — Oceania
Cloudflare Pages (this app)
Anthropic (AI processing)
Clerk (sign-in)
Sentry · PostHog (error + product analytics)
The database sits beside the compute on a private network and is never exposed to the public internet. Browsers run on our own worker, so your logged-in sessions never pass through a third-party browser service.
Standard managed infrastructure — no exotic hosting you'd need to assess separately.
- Page structure and visible content, for classification
- Synthetic inputs and observed outcomes
- Your uploaded docs, for conformance comparison
Never credentials. Never real user data — there isn't any in the pipeline to begin with.
We learn from anonymized failure patterns pooled across customers — e.g. "selector strategies that break on infinite-scroll listings." App identity, URLs, content, and anything traceable to you are stripped before data crosses that boundary. If that isn't acceptable for your organisation, raise it in the pilot conversation.
The questions security reviewers actually ask
Have a question this page doesn't answer? Ask it — the answer goes here, publicly.
Ask a trust questionWhat we ask of your organisation, and what we promise back
The plain-English version of the onboarding agreement. It is deliberately short.