Skip to main content

Security you can verify

We don't ask you to take our word for it. Run any of these independent security scanners yourself and see the results. Every grade is public, every test is repeatable.

Our approach

Security built into every layer

Tidy Names handles registrar API credentials with the same care a bank applies to account numbers. Every layer of the stack is designed to minimize exposure and maximize protection.

Encrypted credentials

Every registrar API key is encrypted at rest using AES-256-GCM with per-credential encryption keys. Credentials are decrypted only at the moment of sync and never stored in plaintext.

Read-only access

Tidy Names only requests the minimum permissions needed to read domain and DNS data. We never modify your domains, change DNS records, initiate transfers, or alter registrar settings.

TLS everywhere

All data is encrypted in transit using TLS 1.3. HSTS is enforced with preload, ensuring browsers always connect over HTTPS. No exceptions, no fallbacks.

Independent verification

Tested and graded by third parties

These are real scores from independent security scanners. Each link takes you to the scanner so you can run the test yourself and verify the results firsthand.

MO

Mozilla Observatory

HTTP security analysis

B+

Tests HTTP headers, cookies, content security policy, cross-origin resource sharing, and subresource integrity.

Run this scan yourself
SL

SSL Labs

TLS configuration

A+

Deep analysis of TLS configuration including certificate chain, protocol support, key exchange, and cipher suite strength.

Run this scan yourself
SH

SecurityHeaders

HTTP security headers

A

Evaluates HTTP response headers including Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, and Permissions-Policy.

Run this scan yourself
HZ

Hardenize

Full-stack security

A

Comprehensive assessment of DNS, email, TLS, and web security configuration in a single report.

Run this scan yourself
IW

ImmuniWeb

Web security & compliance

A

Tests web application security, SSL/TLS implementation, GDPR compliance readiness, and PCI DSS requirements.

Run this scan yourself
LH

Lighthouse

Best practices audit

100

Google Chrome audit covering HTTPS enforcement, mixed content detection, vulnerable JavaScript libraries, and security best practices.

Run this scan yourself

Why two of these are not A+

One test, for one reason. Our Content-Security-Policy allows inline scripts, which costs us 20 points on Observatory and caps SecurityHeaders at A. Removing it means switching to per-request nonces, and a nonce cannot appear in pre-rendered HTML - so every page of this site would have to be generated on demand instead of served as static HTML from a CDN. That is a real, measurable cost in load time, paid for a defence that currently guards nothing: Tidy Names renders no user-authored HTML anywhere, so there is no injection point for the policy to catch.

So we spent the effort on the parts that do bite. An injected script cannot load plugin content, rewrite where relative links point, submit a form off-site, or open a connection to anywhere but our own servers - and the site cannot be framed at all. It is a deliberate trade-off, written down and re-examined on a schedule. The moment this site renders anything a user wrote, it stops being the right call and we change it.

Infrastructure

How we protect your data

Data encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database backups are encrypted with separate keys and stored in geographically redundant locations.

Access control

Production access is restricted to authorized personnel using multi-factor authentication. We follow least-privilege principles and audit all access to production systems.

Minimal data collection

We collect only what is needed to operate the service. No advertising trackers, no third-party marketing cookies. Analytics are privacy-focused and anonymized.

Incident response

In the event of a data breach, affected users are notified within 72 hours with clear guidance on credential rotation and next steps.

Accessibility

Usable by everyone

We build Tidy Names to be accessible to all users, including those who rely on screen readers, keyboard navigation, and assistive technologies. These scores are independently verifiable.

WV

WAVE

Web accessibility evaluation

0 errors

Evaluates page structure, ARIA labels, colour contrast, form labels, alt text, and heading hierarchy against WCAG guidelines.

Run this scan yourself
LH

Lighthouse

Accessibility audit

100

Google Chrome audit covering colour contrast ratios, ARIA attribute validity, document structure, and interactive element accessibility.

Run this scan yourself

Your credentials, protected

Connect your registrar accounts with confidence. Every credential is encrypted, every connection is read-only, and every security grade is public.

Start for free

Free for up to 5 domains. No credit card required.