Security you can verify
We don't ask you to take our word for it. Run any of these independent security scanners yourself and see the results. Every grade is public, every test is repeatable.
Our approach
Security built into every layer
Tidy Names handles registrar API credentials with the same care a bank applies to account numbers. Every layer of the stack is designed to minimize exposure and maximize protection.
Encrypted credentials
Every registrar API key is encrypted at rest using AES-256-GCM with per-credential encryption keys. Credentials are decrypted only at the moment of sync and never stored in plaintext.
Read-only access
Tidy Names only requests the minimum permissions needed to read domain and DNS data. We never modify your domains, change DNS records, initiate transfers, or alter registrar settings.
TLS everywhere
All data is encrypted in transit using TLS 1.3. HSTS is enforced with preload, ensuring browsers always connect over HTTPS. No exceptions, no fallbacks.
Independent verification
Tested and graded by third parties
These are real scores from independent security scanners. Each link takes you to the scanner so you can run the test yourself and verify the results firsthand.
Mozilla Observatory
HTTP security analysis
Tests HTTP headers, cookies, content security policy, cross-origin resource sharing, and subresource integrity.
Run this scan yourselfSSL Labs
TLS configuration
Deep analysis of TLS configuration including certificate chain, protocol support, key exchange, and cipher suite strength.
Run this scan yourselfSecurityHeaders
HTTP security headers
Evaluates HTTP response headers including Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, and Permissions-Policy.
Run this scan yourselfHardenize
Full-stack security
Comprehensive assessment of DNS, email, TLS, and web security configuration in a single report.
Run this scan yourselfImmuniWeb
Web security & compliance
Tests web application security, SSL/TLS implementation, GDPR compliance readiness, and PCI DSS requirements.
Run this scan yourselfLighthouse
Best practices audit
Google Chrome audit covering HTTPS enforcement, mixed content detection, vulnerable JavaScript libraries, and security best practices.
Run this scan yourselfWhy two of these are not A+
One test, for one reason. Our Content-Security-Policy allows inline scripts, which costs us 20 points on Observatory and caps SecurityHeaders at A. Removing it means switching to per-request nonces, and a nonce cannot appear in pre-rendered HTML - so every page of this site would have to be generated on demand instead of served as static HTML from a CDN. That is a real, measurable cost in load time, paid for a defence that currently guards nothing: Tidy Names renders no user-authored HTML anywhere, so there is no injection point for the policy to catch.
So we spent the effort on the parts that do bite. An injected script cannot load plugin content, rewrite where relative links point, submit a form off-site, or open a connection to anywhere but our own servers - and the site cannot be framed at all. It is a deliberate trade-off, written down and re-examined on a schedule. The moment this site renders anything a user wrote, it stops being the right call and we change it.
Infrastructure
How we protect your data
Data encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database backups are encrypted with separate keys and stored in geographically redundant locations.
Access control
Production access is restricted to authorized personnel using multi-factor authentication. We follow least-privilege principles and audit all access to production systems.
Minimal data collection
We collect only what is needed to operate the service. No advertising trackers, no third-party marketing cookies. Analytics are privacy-focused and anonymized.
Incident response
In the event of a data breach, affected users are notified within 72 hours with clear guidance on credential rotation and next steps.
Accessibility
Usable by everyone
We build Tidy Names to be accessible to all users, including those who rely on screen readers, keyboard navigation, and assistive technologies. These scores are independently verifiable.
WAVE
Web accessibility evaluation
Evaluates page structure, ARIA labels, colour contrast, form labels, alt text, and heading hierarchy against WCAG guidelines.
Run this scan yourselfLighthouse
Accessibility audit
Google Chrome audit covering colour contrast ratios, ARIA attribute validity, document structure, and interactive element accessibility.
Run this scan yourselfYour credentials, protected
Connect your registrar accounts with confidence. Every credential is encrypted, every connection is read-only, and every security grade is public.
Free for up to 5 domains. No credit card required.