Compliance
This page states how the free audit handles the URL a visitor enters, which suppliers receive what, and the controls we operate under. The definitions of the scores a report shows are published in the ZAG Standard.
- Applies to
- The free audit and reports on withzag.com
- Last updated
- 2026-09-21
This page is an English translation provided for reference. The Japanese text is the governing version.
01How the public report handles the address you enter
What we fetch. The domain you type and its www and bare-domain pair, and nothing else. We identify ourselves honestly in every request, with a name and a link to a page explaining who we are. We read the site's robots.txt first and obey it; where we cannot read it, we do not crawl the site. We read the site's terms first, and a term forbidding automated access stops the run. We never use a proxy, never pretend to be a browser or a person, and never work around a block: a refusal is recorded in the report as what happened. We fetch at most 25 pages, one at a time.
What we keep, and for how long. We keep your report. The report and the data behind it are our record: they stay in our own store so that you can come back for the full version, and they are confidential — we show them to the person who asked and to nobody else. We do not publish them, do not list them anywhere, do not let a search engine index them, and do not share or sell them. A report has an address that cannot be guessed and that does not contain the domain, there is no page that lists reports, and nothing will answer the question "has anyone run a report on this company". We also keep a copy per domain for 24 hours, so that asking twice in a day does not fetch the site twice, and a counter that limits how often one requester can run reports, a one-way hash kept for the current day only and deleted at the first request after it ends — we do not store the address it came from.
No cookie. The free report uses no cookie. The limit that stops one source generating report after report is applied to a one-way hash of the address a request came from, made with a secret key we hold; we do not store the address itself. If requests from one address keep arriving in quick succession after its limit is reached, on three consecutive days, we stop accepting requests from that address for 30 days, and for that alone we keep a similar hash with no date in it, only while the decision and the block last (33 days at most).
The list in your browser. So that you can open your own reports again, the site keeps their links, the domain and the time, up to twenty, in your browser's own storage (local storage). They are never sent to us, and you can clear them from the page at any time.
What we do not collect. The free report involves no cookie, no account, no login, no email address, no analytics identifier, no third-party script and no identification by combining your device's characteristics. We send you the opening section only until you unlock the rest. At the unlock you give us your name, your company and your work email. We use them for two things and say so beside the button that accepts our terms: to deliver your report and contact you about it, and to contact you about our services. They do not appear in the report or in the PDF — they are held separately as the record of your request. Ask us to stop the contact or to delete them and we do both, and every message we send says how to stop. Inside our company the people who contact you may hold the same details for that purpose, and a deletion reaches that copy too.
How to have it deleted. Send us the link to the report and we will delete our copy and confirm when it is done; if you no longer have the link, we will take the request in a way we can verify. What we will not do is tell anyone who cannot show the link whether a report exists for a given domain — that answer would be a way to find out who has been looked at. One limit we will not pretend away either: the search-data supplier in the table above keeps the queries we sent to it for 365 days under its own policy, and publishes no way to have them removed sooner. Our deletion ends our copy, not theirs.
The PDF is the same record in another form. It is rendered from the same data, held under the same address and the same marking, and reaching it needs both that address and the acceptance the full report was released against.
What the report is. It is generated from public sources without the involvement of the site's owner. They have not seen it, have not reviewed it and have not agreed with it. It is not a deliverable we sold to anyone. Every number in it is defined by our published standard, and the version of the standard it was scored against is printed on the report.
02Who processes data for us
These are the companies that handle data on our behalf, what we send them, and where it goes. A company not on this list receives nothing.
| Company | What we use it for | What we send | Where | How long they keep it |
|---|---|---|---|---|
| Microsoft Azure | Hosting the application and its database | Everything the application holds for a customer, including personal data | At rest in Japan; support access may be global | For the life of the engagement, then deleted with the project |
| GitHub | Our source code and work tracking | Code, requirements and issues. No customer records, by policy | United States | For the life of the company |
| Anthropic | The assistant sessions that do the work, and model calls inside it | A manufacturer's product documents and the questions we ask about them | United States | Not used to train their models, under their commercial terms |
| OpenAI | Measuring what ChatGPT answers about a manufacturer | The questions, and product documents where the task needs them | United States | Not used to train their models, under their API terms |
| Measuring what Gemini answers; reading a customer's own Search Console with their grant | The questions; the customer's own search data | United States and global | Under the Gemini paid-tier terms, prompts and responses are not used to improve their products | |
| DataForSEO | Search results, AI-answer data and keyword data, for the public report and for measurement | A domain name and search terms. No personal data | Estonian company; infrastructure in the United States and Germany; an operations office in Ukraine | 365 days, then deleted permanently. They publish no earlier deletion procedure |
Two kinds of supplier are listed in our internal register but not engaged, so they appear here only when they are: a service that resolves a visitor's network address to an organisation, and the external people who verify work or place content, each under an individual agreement.
03The controls we run
- Every change is reviewed by someone other than its author before it reaches our main branch, and anything touching authentication, data, infrastructure or the build is reviewed by the person responsible for security.
- Secrets live only in a managed key store. They are never written in code, configuration, test data, logs or tickets, and an automated check blocks a change that would do so.
- Dependencies are pinned, scanned on every change, and reviewed weekly against published vulnerabilities; anything critical is patched within seven days.
- A customer's data is isolated per project, and personal data is held in Japan.
- Every number we report carries its method and the run that produced it. A number without one is rejected by the system rather than published.
- A refusal is recorded, never circumvented. If a site or a service declines us, that is what the report says.
- We never send outreach on a customer's behalf, and we never send a public report to the company it is about.
- Deletion is a route, not a promise: a request resolves through code that removes the records and leaves only counts and dates behind.
- We run an information-security management system built to ISO/IEC 27001 Annex A, with a statement of applicability covering all 93 controls and dated evidence behind each one we claim. We are not certified today, and we will not say otherwise until a certificate exists.
04Score definitions
Every score a report shows is defined in the published ZAG Standard. For each score it states what is measured, from which data, and by which calculation.