Compliance

This page states how the free audit handles the URL a visitor enters, which suppliers receive what, and the controls we operate under. The definitions of the scores a report shows are published in the ZAG Standard.

Applies to
The free audit and reports on withzag.com
Last updated
2026-09-21

This page is an English translation provided for reference. The Japanese text is the governing version.

01How the public report handles the address you enter

What we fetch. The domain you type and its www and bare-domain pair, and nothing else. We identify ourselves honestly in every request, with a name and a link to a page explaining who we are. We read the site's robots.txt first and obey it; where we cannot read it, we do not crawl the site. We read the site's terms first, and a term forbidding automated access stops the run. We never use a proxy, never pretend to be a browser or a person, and never work around a block: a refusal is recorded in the report as what happened. We fetch at most 25 pages, one at a time.

What we keep, and for how long. We keep your report. The report and the data behind it are our record: they stay in our own store so that you can come back for the full version, and they are confidential — we show them to the person who asked and to nobody else. We do not publish them, do not list them anywhere, do not let a search engine index them, and do not share or sell them. A report has an address that cannot be guessed and that does not contain the domain, there is no page that lists reports, and nothing will answer the question "has anyone run a report on this company". We also keep a copy per domain for 24 hours, so that asking twice in a day does not fetch the site twice, and a counter that limits how often one requester can run reports, a one-way hash kept for the current day only and deleted at the first request after it ends — we do not store the address it came from.

No cookie. The free report uses no cookie. The limit that stops one source generating report after report is applied to a one-way hash of the address a request came from, made with a secret key we hold; we do not store the address itself. If requests from one address keep arriving in quick succession after its limit is reached, on three consecutive days, we stop accepting requests from that address for 30 days, and for that alone we keep a similar hash with no date in it, only while the decision and the block last (33 days at most).

The list in your browser. So that you can open your own reports again, the site keeps their links, the domain and the time, up to twenty, in your browser's own storage (local storage). They are never sent to us, and you can clear them from the page at any time.

What we do not collect. The free report involves no cookie, no account, no login, no email address, no analytics identifier, no third-party script and no identification by combining your device's characteristics. We send you the opening section only until you unlock the rest. At the unlock you give us your name, your company and your work email. We use them for two things and say so beside the button that accepts our terms: to deliver your report and contact you about it, and to contact you about our services. They do not appear in the report or in the PDF — they are held separately as the record of your request. Ask us to stop the contact or to delete them and we do both, and every message we send says how to stop. Inside our company the people who contact you may hold the same details for that purpose, and a deletion reaches that copy too.

How to have it deleted. Send us the link to the report and we will delete our copy and confirm when it is done; if you no longer have the link, we will take the request in a way we can verify. What we will not do is tell anyone who cannot show the link whether a report exists for a given domain — that answer would be a way to find out who has been looked at. One limit we will not pretend away either: the search-data supplier in the table above keeps the queries we sent to it for 365 days under its own policy, and publishes no way to have them removed sooner. Our deletion ends our copy, not theirs.

The PDF is the same record in another form. It is rendered from the same data, held under the same address and the same marking, and reaching it needs both that address and the acceptance the full report was released against.

What the report is. It is generated from public sources without the involvement of the site's owner. They have not seen it, have not reviewed it and have not agreed with it. It is not a deliverable we sold to anyone. Every number in it is defined by our published standard, and the version of the standard it was scored against is printed on the report.

02Who processes data for us

These are the companies that handle data on our behalf, what we send them, and where it goes. A company not on this list receives nothing.

CompanyWhat we use it forWhat we sendWhereHow long they keep it
Microsoft AzureHosting the application and its databaseEverything the application holds for a customer, including personal dataAt rest in Japan; support access may be globalFor the life of the engagement, then deleted with the project
GitHubOur source code and work trackingCode, requirements and issues. No customer records, by policyUnited StatesFor the life of the company
AnthropicThe assistant sessions that do the work, and model calls inside itA manufacturer's product documents and the questions we ask about themUnited StatesNot used to train their models, under their commercial terms
OpenAIMeasuring what ChatGPT answers about a manufacturerThe questions, and product documents where the task needs themUnited StatesNot used to train their models, under their API terms
GoogleMeasuring what Gemini answers; reading a customer's own Search Console with their grantThe questions; the customer's own search dataUnited States and globalUnder the Gemini paid-tier terms, prompts and responses are not used to improve their products
DataForSEOSearch results, AI-answer data and keyword data, for the public report and for measurementA domain name and search terms. No personal dataEstonian company; infrastructure in the United States and Germany; an operations office in Ukraine365 days, then deleted permanently. They publish no earlier deletion procedure

Two kinds of supplier are listed in our internal register but not engaged, so they appear here only when they are: a service that resolves a visitor's network address to an organisation, and the external people who verify work or place content, each under an individual agreement.

03The controls we run

  • Every change is reviewed by someone other than its author before it reaches our main branch, and anything touching authentication, data, infrastructure or the build is reviewed by the person responsible for security.
  • Secrets live only in a managed key store. They are never written in code, configuration, test data, logs or tickets, and an automated check blocks a change that would do so.
  • Dependencies are pinned, scanned on every change, and reviewed weekly against published vulnerabilities; anything critical is patched within seven days.
  • A customer's data is isolated per project, and personal data is held in Japan.
  • Every number we report carries its method and the run that produced it. A number without one is rejected by the system rather than published.
  • A refusal is recorded, never circumvented. If a site or a service declines us, that is what the report says.
  • We never send outreach on a customer's behalf, and we never send a public report to the company it is about.
  • Deletion is a route, not a promise: a request resolves through code that removes the records and leaves only counts and dates behind.
  • We run an information-security management system built to ISO/IEC 27001 Annex A, with a statement of applicability covering all 93 controls and dated evidence behind each one we claim. We are not certified today, and we will not say otherwise until a certificate exists.

04Score definitions

Every score a report shows is defined in the published ZAG Standard. For each score it states what is measured, from which data, and by which calculation.