Trust
Security, data, legal notice, terms.
Trust
Security and data
What Avalyz does with your data, in a few lines. This page is read-only: it asks you for nothing.
What a test does
- Quick mode: 4 pages read-only without an account, 6 with an account, results in a few minutes.
- Full mode: the whole site, up to the plan's cap: 20 pages without an account, Starter 20, Pro 100, Team 500.
- Optional test account: Avalyz signs in with the credentials you give (signing in is the only form submitted), explores the signed-in pages and records the journeys by role without playing them.
- 13 levels, with their maturity stated plainly: solid (accessibility, visual and languages, performance, resilience); real passive checks (security, compliance); real with a test account (end-to-end by role); partial (API, data, business logic, static); inventory only (unit, component).
- Read-only by default: nothing is created or changed on your app. Write mode, only at your request, fills in and submits forms with test data: it requires proof that the site is yours (production) or your attestation that you have the right to test it (test environment), and never makes a real payment or deletes anything. The test account's password stays in memory for the test, then it is erased.
- Only public addresses are accepted.
What is kept, and for how long
| Data | Duration |
|---|---|
| Report of a free test without sign-up (tested address, screenshots, findings) | 24 hours, then automatic deletion: a free test is not kept. To keep your reports, choose a plan. |
| Reports of a subscriber's tests (run from the website) | The latest 10 tests on Starter, 30 on Pro, 100 on Team; an older test is deleted 24 hours after it ran. |
| Account test report (tested address, screenshots, findings) | 30 days, then automatic deletion. The most recent report of each site is kept: ask for its deletion if you want it gone. |
| Test account (sign-in page, username, password) | The password stays in memory for the test, then it is erased: it is never written into Avalyz's data. |
| IP address (limit of 3 free tests a day) | 24 hours, in memory only: it is not written to Avalyz's data. |
| Sign-in link | 15 minutes, single use. |
| Open session (cookie) | 14 days, or until you sign out. |
| Account (e-mail address, plan, subscription status) | As long as the account exists. Deleted on your request. |
| Waiting list (address, date, consent) | Until you unsubscribe. The link in each e-mail deletes your address. |
| Referral code (cookie) | 90 days in your browser. It is counted without saying anything about you. |
| Visit and sign-up counters | 400 days. Numbers per day, with no IP address or identity. |
Payment
Payment goes through a reference merchant (Polar). Avalyz never receives a card number.
Where the data is
Hosted by Scaleway, in Paris (France), in the European Union.
Never resold
- Avalyz does not sell or rent any data.
- No data is given to advertising networks.
Delete your data
- A report: write to us with the address of the tested site, and we delete it.
- Your account: write to us from the account's address, and we delete the account and its reports.
- The waiting list: the unsubscribe link, in each e-mail, deletes your address at once.
How Avalyz tests your app
- Read-only by default: Avalyz only sends read requests (GET and HEAD) and, with a test account, the sign-in is the only form submitted. Write mode, only at your request, fills in and submits forms with test data: it requires proof that the site is yours (production) or your attestation that you have the right to test it (test environment), and never makes a real payment or deletes anything.
- No attacks: no brute force, no denial of service, no attempt to exploit a flaw. The security checks read what your site answers to ordinary visits.
Deeper checks: only on a site you have proven you own
Two checks go further: reading your database (Supabase, Firebase) with the page's public key, read-only, and a graduated load test (10, 25, 50 simultaneous visits to the home page).
They only run once you have proven the site is yours: the avalyz-verification tag on the home page, or the file /.well-known/avalyz-verification.txt. Without proof, Avalyz only reports what the page publishes.
Your source code
If you give your repository address, Avalyz makes a copy for the time of the analysis, reads the files, counts your tests, then deletes the copy.
Avalyz runs your code only if you ask for it ("run my tests" option) and after ownership proof: in an isolated sandbox, with no network access, wiped at the end. Without both, your repository is only read.
Proof of diligence for write mode
When you turn on write mode or run a test, we record your account identifier, your e-mail, the date and time, your IP address, your browser, the targeted address and environment, the accepted attestation (text and version), the identifier of the test account provided (never its password) and the list of actions performed.
- Why: to perform the contract safely and prove who authorized each test, to prevent abuse and defend our rights or those of application owners (legitimate interest; performance of the contract).
- How long: 5 years after the test, then deletion.
- Recipients: our hosting provider; the authorities upon a lawful request; the owner of an application tested without authorization, to the extent necessary.
- Your rights: access, rectification and objection, by writing to us; erasure may be deferred as long as this data is needed to establish, exercise or defend legal claims. You can contact the data protection authority of your country (in Morocco, the CNDP). contact@avalyz.com
Backups
Avalyz data is backed up every day, in Paris, with an integrity fingerprint. The last 3 backups are kept: deleted data may remain in them until they are rotated out.
Report a vulnerability
Found a vulnerability in Avalyz? The security contact is published here (RFC 9116 standard): /.well-known/security.txt
Or write to us: contact@avalyz.com
Contact
For any question or deletion, write to: contact@avalyz.com
Company
Legal notice
Who publishes Avalyz, who hosts it, and how to reach us.
Publisher
Avalyz is published by Framework SARL AU, a single-member limited liability company under Moroccan law.
| Registered office | Casablanca, Maroc |
|---|---|
| Trade register | RC Casablanca 333221 |
| Common company identifier (ICE) | 000738993000089 |
| Publishing director | the manager of Framework SARL AU |
Hosting provider
Scaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris (France). Data hosted in Paris, in the European Union.
Payment
Payments are collected by Polar Software Inc., merchant of record: it issues the invoices and collects the applicable taxes. Avalyz never receives any card number.
Intellectual property
The Avalyz software, its reports, texts and brand are the property of Framework SARL AU. The reports produced for you are yours to use: you may share them and pass them on to anyone you like.
Personal data
What Avalyz keeps, for how long and how to delete it is described on the Security and data page. Security and data
Contact
For any question: contact@avalyz.com
Company
Terms of sale and use
What you buy, what Avalyz commits to, and what it does not promise. Version 2, in force since 2026-10-08.
1. The service
Avalyz tests a web application from the outside and produces a report of findings. By default, the test is read-only. On a non-production environment that you designate, you can turn on write mode: Avalyz then creates test accounts, fills in and submits forms and creates test data, all prefixed "avalyz-test". Even in write mode, Avalyz never makes a real payment and never deletes any data. Avalyz does not guarantee the absence of defects: it proves what it saw.
2. The account
An account is personal, or belongs to a team you invite.
3. Authorization and attestation
3.1 You only test applications you own, or for which you have obtained the written authorization of their owner, covering the type of test you run.
3.2 To turn on write mode outside production, you provide a test account on the target application and tick the attestation provided. For any production target, you must also prove your technical control of the domain (tag or file).
3.3 Your attestation is a statement of fact for which you alone are answerable. Avalyz may ask you at any time for proof of the authorization and suspend the test in the meantime.
4. Acceptable use
Use of Avalyz is subject to the Acceptable use policy, which is part of these terms. In particular, it is forbidden to: test a third party's application without its written authorization; run a write-mode test on a production environment without technical proof; exceed the declared or displayed load limits; use Avalyz to bypass an access protection.
5. Price, payment and cancellation
Prices are shown in US dollars, taxes included, on the Pricing page. Subscriptions are paid in advance, per period, with no commitment: you can stop at any time and access stays open until the end of the paid period. Payment is collected by Polar Software Inc., merchant of record, which issues the invoice.
6. Free trial and quotas
The free test without sign-up and the 14-day trial are offered within the limits stated on the site. Each plan has a monthly test quota and a number of pages per test; beyond that, the test stops and the report says so.
7. Refunds
Money-back guarantee: if Avalyz is not right for you, ask by e-mail within 14 days of your first payment and you get a full refund, no questions asked. Later payments are not refunded pro rata: you keep access until the end of the paid period. Refunds go through the merchant of record, to the payment method used.
8. What Avalyz does not promise
A report with no finding does not mean your application is defect-free: what was not tested is not covered. Avalyz is not liable for decisions taken on the basis of a report.
9. Your responsibility and indemnity
9.1 You alone are responsible for the choice of targets, the accuracy of your attestation and the use you make of Avalyz and its reports.
9.2 If you act as a professional, you indemnify Framework SARL AU against any claim, penalty, judgment and all reasonable costs (including defence costs) arising from a test you ran without authorization, an inaccurate attestation or a breach of the Acceptable use policy. Framework notifies you of any claim without delay and lets you take part in the defence.
10. Limitation of liability
10.1 The total liability of Framework SARL AU, for all causes combined, is limited to the amounts you paid for Avalyz during the twelve months preceding the event giving rise to the claim.
10.2 Framework is not liable for indirect damages (loss of revenue, of unsaved data, of reputation), nor for the consequences of a test run without authorization.
10.3 These limits do not apply in case of wilful misconduct, fraud or gross negligence by Framework, nor to bodily injury, nor to the extent the applicable law forbids them. If you are a consumer, the rights that the law of your country guarantees you and that cannot be waived remain intact.
11. Evidence and logs
To prove who ran which test, on which target and with which authorization, Avalyz records, each time write mode is turned on and for each test: your account identifier, your e-mail, the date and time, your IP address, your browser, the target address, the declared environment, the text and version of the accepted attestation, the identifier of the test account provided (never its password) and the list of actions performed. These records are binding between us unless proven otherwise. They are kept for five years after the test, then deleted.
12. Data
The data processed, how long it is kept and how to delete it are described on the Security and data page, which is part of these terms.
13. Suspension and termination
Avalyz may immediately suspend a test or an account in case of serious suspicion of unauthorized use, a report from an owner, an inaccurate attestation or a risk to a system. You are told the reason, unless the law forbids it, and you can prove your authorization. In case of a proven serious breach, Avalyz may terminate your account without refunding the current period, subject to your statutory consumer rights.
14. Cooperation with authorities
Framework responds to requests from the competent judicial or administrative authorities and may give them the records described in the "Evidence and logs" article. Framework may also give them to the owner of an application tested without authorization, to the extent necessary to defend that owner's rights or its own.
15. Governing law and jurisdiction
These terms are governed by Moroccan law. Failing an amicable agreement within 30 days, any dispute falls under the Commercial Court of Casablanca. If you are a consumer, you keep the protection of the mandatory rules of your country of residence and the right to go to the courts those rules designate.
Acceptable use policy
Avalyz is for testing your own applications. To keep it safe for everyone:
- Your target, your authorization. You only test what belongs to you, or what its owner has authorized you, in writing, to test.
- Write mode outside production. Write mode is used on a test environment, with a test account you provide. In production, technical proof of control of the domain is mandatory.
- No bypassing. You may not use Avalyz to get past an authentication, exploit a vulnerability, or collect or modify third-party data.
- Reasonable load. You respect the displayed or declared limits on pages, frequency and load.
- Test data only. No real personal data of third parties in forms; Avalyz uses fictitious data prefixed "avalyz-test".
- Report abuse. Is a test targeting your site without your consent? Write to us with the targeted address and the time: we suspend, check and reply to you within 2 business days. contact@avalyz.com
Any breach may lead to the immediate suspension of the test or the account and engages your liability.
Contact
For any question: contact@avalyz.com · Legal notice