SpotCheck trust centre
SpotCheck is operated by SpotDev Services Ltd. This page summarises the security, privacy and data-handling boundaries that support the audit product.
Read-only audit boundaries
- HubSpot portal audits use OAuth scopes for read and search operations. SpotCheck does not write to customer HubSpot portals.
- Website audits use public URL crawling, browser rendering and public performance sources. They do not perform active security scanning.
- Report invitations require a unique authenticated account. There are no anonymous public report links.
AI and manual verification
AI is advisory and non-scored. Current final-review claims must cite known evidence IDs and pass validation before display. Historical AI observations are labelled as hypotheses unless an authorised reviewer records a validation outcome.
Retention and deletion summary
Raw audit evidence is time-limited and separate from completed reports. Reports, findings, action-workspace records, invitations and audit logs are retained until a report or account deletion instruction applies, subject to safety checks such as deleting stored CRO screenshot objects before their database rows. Analytics and feedback use stable identifiers and avoid raw customer content.
What SpotCheck does not claim
- It does not guarantee exact ROI, traffic, search ranking, ad performance or competitor market share.
- It does not prove every workflow branch, conditional field, hidden page or private record state.
- It does not treat dismissed feedback as automatic truth without review.
- It does not connect customer data to third-party analytics or collaboration tools.
Policies and contact
- SpotCheck methodology
- SpotCheck privacy policy
- Security and privacy information
- SpotDev Privacy Policy
- SpotDev Data Processing Agreement
- SpotDev Cyber Security Policy
Security concerns can be sent to hello@spotdev.co.uk. Do not include passwords, tokens, customer records or other secrets in the first message.