Trust
Security & trust
Everything on this page is already enforced in the product or stated in our Privacy Policy — this is the short version, written for the person doing the security review.
Agents never move real money
Hard guardrail: agents stop at payment forms and never submit real payment data or place a real order. Full checkouts run only on your staging environment, with test cards you provide.
Your data trains nothing
Site content, screenshots, and reports are processed to deliver the service — never used to train AI models, by us or by our AI providers under our commercial API terms.
Verified owners only
Agents only test sites you've proven you control via DNS record or meta tag. Competitor lookalikes are strictly read-only — no form submissions on unverified sites.
Every run is capped
Per-agent step caps, token budgets, and hard timeouts. A run shows its cost ceiling before launch and can't exceed it.
What agents can and cannot do
mocktomer's AI customers browse your site in isolated, short-lived browser containers. Their behavior is bounded by guardrails that are enforced at runtime, not just prompted:
- No real payments, ever. Agents test checkout and payment flows up to the point of payment, then stop and report. Real card entry and order placement are blocked; end-to-end purchases run only on staging environments you designate, with test cards you provide.
- Verified sites only. Interactive testing requires proof of ownership (DNS record or meta tag). Unverified sites — e.g. competitor comparisons — are read-only: no form fills, no submissions.
- Hard resource caps. Per-agent step limits, token budgets, and a hard job timeout. Runs show a cost ceiling before launch and auto-stop at it.
- Full audit trail. Every step each agent takes — screenshot plus reasoning — is stored with the run and visible to you. Nothing about a finding is a black box.
Your data
Content from sites you submit (page content, screenshots, journey context) is processed by AI providers such as Anthropic solely to generate your journeys and reports. We do not use your data, your sites' content, or your reports to train AI models, and our AI providers process it under commercial API terms that do not permit provider-side training on our customers' data.
Data is encrypted in transit (TLS) and at rest on Google Cloud Platform. Payments are handled by Stripe — card details never touch our servers. Secrets live in Google Secret Manager, and production services run under least-privilege service accounts with no long-lived keys.
Subprocessors
| Provider | Purpose | Region |
|---|---|---|
| Google Cloud Platform / Firebase | Cloud infrastructure, hosting, authentication, database, file storage, secret storage | United States (us-central1) |
| Anthropic | AI model inference for journey simulation and report generation — no training on customer data under commercial API terms | United States |
| Stripe | Payment processing and billing — mocktomer never stores your card details | United States |
The full list, including operational tooling, is maintained in our Privacy Policy §5.
International transfers
We operate from the United States. Where GDPR/UK GDPR applies, transfers rely on the European Commission's Standard Contractual Clauses implemented by our providers. Details in Privacy Policy §13.
Billing honesty
You're charged only when an AI customer delivers a verdict. Journeys that fail on our side are on us. No metered overages, no silent charges — running out simply asks you to top up.
For enterprise & agency reviews
DPA, subprocessor list, and this security overview are ready to send — no NDA required. We're a young company and say so plainly: no SOC 2 report yet; what we offer instead is a small, fully documented surface area and full journey transcripts you can audit yourself. Email support@mocktomer.ai.
Report a vulnerability
Found something? Email support@mocktomer.ai with “Security report” in the subject. We read every report, respond fast, and won't take legal action against good-faith research.