Are you found by AI? Log in Free scan

Updated 8 September 2026

Trust you can inspect.

The providers behind the service. The checks we have run. The limits we still need to test.

Powered by Stripe

Payments: Stripe

Card details are secured by Stripe and never shown to us. You enter them on Stripe’s checkout page. We receive identifiers and payment events to manage your account.

Stripe’s PCI Level 1, SOC 1 and SOC 2 information →
Protected by Cloudflare

Hosting: Cloudflare

Our hosted service runs on Cloudflare Workers. Cloudflare reports ISO 27001, ISO 27701, SOC 2 Type II and PCI DSS coverage for its platform.

Cloudflare’s compliance information →

Email: Resend

We use Resend to deliver service emails. Resend reports SOC 2 Type II compliance and describes its GDPR controls.

Resend’s security information →

These are our providers’ certificates, not ours. Our own checks are dated below.

Your data and access

We store the website and email you provide, measurement questions, saved answers and report history. Your private report and console links act as access keys: share them only with people you intend to give access. Our privacy policy describes data use and service providers.

Operator routes require authorisation through configured Cloudflare Access or operator-key controls. The product also uses scan rate limits, Turnstile verification and measurement budgets. These controls reduce specific risks; they do not establish that the whole system has passed a penetration test.

Completed checks

8 September 2026 · Internal automated tests

Stripe webhook signature verification

30 regression assertions passed, covering valid signatures, rejected malformed timestamps, tolerance boundaries and multiple signatures. Two edge cases found during the review were fixed.

Read the test scope, result and limitations →

8 September 2026 · Public repository

OpenSSF Scorecard

Our public thl-open repository scored 4.9/10 on automated repository and software-supply-chain checks. This measures repository practices, not the security of the hosted product. Findings include dependency pinning and branch protection.

Read the dated Scorecard result →

9 September 2026

Published skills scanned weekly

Our published skills are scanned every week with Cisco AI Defense's open-source skill scanner, run on a hosted Linux runner with isolation checks. This week: 17 skills, 22 medium and 17 informational findings, no errors; the findings are dependency pinning and documented network use in one skill, and they stay listed rather than hidden. This scans skill packages for known patterns; a clean scan does not prove a skill is safe.

What we are testing next

MCP and staging-application tests remain in progress. These are not completed external audits; each report will state its date, scope and limitations.

How we use agents

Authorised agents help review reports, write code and carry out approved actions, including sending emails and deploying changes. Task ownership, instructions and review requirements define their scope. These are workflow controls, not proof of operating-system isolation.

Some agent tools share a macOS user account. Separate workspace directories do not prevent cross-workspace access by that user. A disposable offline runner has been tested on synthetic tasks; that test does not establish isolation for the wider connected fleet.

Open to inspection

Our readiness method and audit suite are open source under the MIT licence. The hosted visibility engine is not open source.

Read the method and audit suite →

Report a security concern

Email hello@techhorizonlabs.com with “Security report” in the subject. Please describe the affected page and reproduction steps without including passwords, private report links or other people’s data.

Machine-readable security contact →

We do not claim SOC 2, ISO 27001 or PCI certification for Found by AI, or an external penetration test. A passing test covers its stated scope, not every possible vulnerability.