Typosquatting.ai
HOW THE SITE IS RUN

Trust and Security

Plain statements about data and security, each one true of the code as it runs today. Nothing here is a certification.

by Typosquatting.ai ResearchLast updated 6 October 2026

What the checker does with a domain you enter

A public check runs as a background job and its finished report is stored for 24 hours under the checked domain, then deleted by a scheduled sweep; individual record lookups are cached in server memory for 15 minutes. The generated candidates go to the discovery engine (our own Worker), Cloudflare’s DNS resolver, crt.sh, the relevant registry’s RDAP service and urlscan.io’s search API from our servers, so those providers see our address, not yours. It never loads a suspect website to read what is on it, and never submits a new scan to any third party. A name on a public hosting platform receives one request to confirm it is claimed, and nothing from the response is stored.

What the panel stores

Your email address, your watchlist, the reports you run for as long as your plan keeps them, the review status you assign to each finding with its first- and last-seen dates, an activity log of your own actions without IP addresses, and a hashed copy of any API key. Sign-in links are single-use and expire after 15 minutes; sessions last 30 days. Everything can be exported as JSON or deleted from Settings, and deletion is immediate.

How the site is secured

All traffic is served over HTTPS with a content security policy that allows scripts and styles from this site only. Session tokens, sign-in tokens and API keys are stored as SHA-256 hashes, so a copy of the database does not contain usable credentials. Every form in the panel carries a per-session token against cross-site request forgery. Sign-in links are confirmed by a button press, so mail scanners that prefetch links cannot spend them. Rate limits apply to sign-in requests, scans and the API.

Payments and email

Paid plans are billed by Stripe, a PCI DSS Level 1 service provider; card details are entered on Stripe’s pages and never reach this site, which stores only the Stripe customer and subscription identifiers. Sign-in links and alert emails are sent through Cloudflare Email Sending, from the Cloudflare account that hosts the service. Both process data under their own security programmes, linked below.

Who is responsible

Cyber Deans Ltd, trading as Typosquatting.ai, is the data controller under UK data-protection law for the processing described in the privacy policy. It is registered in England and Wales under company number 12784136. The privacy policy sets out your rights and how to exercise them, and the Information Commissioner’s Office is the supervisory authority.

Reporting a vulnerability

Security researchers can find the security contact in security.txt at the standard well-known path and on the contact page, together with our operator’s disclosure policy. Please give us reasonable time to investigate before publishing, and do not access other people’s data while testing. We do not run a bug-bounty programme.

If something goes wrong

If we learn of a security incident that affects your data, we will tell affected accounts by email as soon as we understand what happened, and record the incident here. There have been no incidents to record since the panel launched on 9 September 2026.

Sources and further reading

  1. RFC 9116: security.txt
  2. Stripe: security at Stripe
  3. Cloudflare: Trust Hub
  4. Information Commissioner’s Office (ICO)
  5. Typosquatting.ai: privacy policy