Scanner Ethics and Responsible Scanning Policy
Last updated: 5 July 2026
1. Purpose
ComplyPages reviews public website transaction flows to identify visible accessibility risks and create developer-ready observations.
This policy explains how we aim to scan and review websites responsibly, safely, and respectfully.
Our goal is to help website teams improve accessibility without disrupting their systems, collecting private customer data, or performing security testing.
2. Scope of review
ComplyPages focuses on public-facing customer flows, such as:
- E-commerce product, cart, and checkout pages;
- Hotel and travel booking flows;
- Ticketing and event purchase flows;
- Online course enrollment and payment flows;
- Quote request and booking forms;
- Login or account-entry pages where publicly accessible;
- Contact and lead forms;
- Accessibility statements and public policy pages.
3. What we do
When reviewing a website, we may:
- Visit public pages;
- Follow visible public links;
- Open public checkout, booking, form, or ticketing flows where safe;
- Capture screenshots or visual references;
- Inspect page structure and accessibility attributes;
- Record URLs, element descriptions, and issue observations;
- Use automated accessibility checks;
- Perform manual review of selected public flow states;
- Prepare developer-ready findings and suggested acceptance criteria.
4. What we do not do
Unless expressly agreed in writing and legally authorised, ComplyPages does not:
- Bypass login, authentication, CAPTCHA, paywalls, or access controls;
- Access private admin panels or customer accounts;
- Make real purchases;
- Submit sensitive, payment, medical, legal, or record-creating forms;
- Create fake customer records;
- Attempt to exploit vulnerabilities;
- Perform penetration testing;
- Probe for security weaknesses;
- Use credential stuffing, password guessing, or account takeover methods;
- Circumvent rate limits or technical protections;
- Scrape websites for unrelated commercial data;
- Collect private customer data intentionally;
- Modify, delete, or interfere with website content or systems.
5. Safe form handling
For public forms, ComplyPages may review visible labels, instructions, keyboard behaviour, validation behaviour, focus order, and error states where this can be done safely.
We avoid submitting forms that would:
- Create a real account;
- Place an order;
- Make a booking;
- Reserve inventory;
- Trigger payment;
- Send a message to a third party;
- Create a support ticket;
- Store sensitive personal data;
- Change records in the website owner’s system.
Where form submission is necessary for a paid engagement, it must be agreed in advance and performed using safe test data or a test environment where possible.
6. Public-page screenshots
ComplyPages may capture screenshots of public pages or selected flow states as evidence for accessibility observations.
Screenshots are used for issue documentation, reproduction context, developer-ready reports, retesting comparison, monitoring history, and quality review.
Screenshots may incidentally include public page content or publicly visible personal data. We do not use screenshot content for unrelated profiling, resale, advertising, or data enrichment.
7. Rate limiting and system respect
ComplyPages aims to use reasonable review volumes and avoid unnecessary load on websites.
We do not intentionally overload, stress test, attack, or disrupt systems.
If a website owner reports that our activity is causing a problem, we will review the issue and take appropriate action.
8. Robots, access rules, and blocking
ComplyPages is intended for safe public-page accessibility QA.
Where technically practical and consistent with the requested service, we aim to respect reasonable access controls, blocking requests, and website-owner preferences.
If you are a website owner and want to ask questions or request that ComplyPages avoid scanning your website, contact:
scan-optout@complypages.com Alternative contact: hello@complypages.com
9. Authorisation
Users requesting scans or paid reviews must have authority to request review of the relevant website, brand, flow, or digital property.
You must not use ComplyPages to scan, monitor, or report on websites where you lack appropriate authorisation, unless the activity is limited to a lawful and ethical public-page observation that does not involve misuse, harassment, security probing, or competitive abuse.
ComplyPages may refuse or stop a scan if authorisation, safety, legality, or ethics are unclear.
10. Vulnerability or sensitive-data discovery
ComplyPages is not a security testing service. If we accidentally observe a serious security issue, exposed sensitive data, or a privacy risk during normal accessibility review, we will not exploit it.
Where appropriate and practical, we may notify the website owner or responsible contact using reasonable disclosure principles.
11. Third-party platforms
Many website flows include third-party platforms, such as booking engines, payment processors, ticketing systems, forms, widgets, consent banners, maps, videos, or chat tools.
ComplyPages may identify visible accessibility issues involving those components, but we do not control them and do not attempt to bypass their security or access controls.
12. Monitoring
Monitoring is limited to selected public flows and agreed checks. It is not continuous security monitoring, uptime monitoring, legal monitoring, or full accessibility certification.
13. Abuse prevention
ComplyPages may refuse requests that appear to involve:
- Harassment;
- Unauthorised surveillance;
- Competitor misuse;
- Mass scraping unrelated to accessibility;
- Security probing;
- Fraud;
- Spam;
- Illegal activity;
- Attempts to collect personal data;
- Attempts to disrupt websites.
14. Relationship with other legal pages
This policy should be read together with:
- Privacy Policy: /privacy
- Legal Disclaimer: /legal/disclaimer
- Terms of Service: /legal/terms
- Data Processing Addendum: /legal/data-processing-addendum
15. Contact
Scanner ethics and opt-out contact: scan-optout@complypages.com General contact: hello@complypages.com
Operator: Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland.