Skip to main content

Trust

Data & security

What AgentReady sends to AI providers, what it stores, and what is public by design. Written to be read, not skimmed past.

What we send to AI providers

To measure how AI engines represent a brand, AgentReady sends prompts to ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), Perplexity and Grok (xAI). Prompts are built from the domain you submit and, for some features, public text from that website.

Do not submit confidential, regulated or private information. Anything you type into a field that is used to build a prompt (for example a brand name, category or competitor) can be sent to those providers.

What we store

Your account details, the domains you add, audit results (scores, the prompts that were asked, the engine responses and mention flags), and anything you generate in the product, such as reports, experiments, llms.txt files and schema markup.

Deleting a domain removes its audits and the evidence rows tied to it. To delete your account data, contact support from the email address on your account.

Sign-in

Sign-in and sessions are handled by Clerk. You can sign in with Google or with an email and password, and sign-up forms use bot protection. AgentReady does not see or store your password.

What is public by design

Shared report links: a shared report is a frozen snapshot with an unguessable address. You can set an expiry and you can delete the link at any time. Shared report pages can be indexed by search engines unless the link has expired or been deleted, so do not share a report you would not want found.

Hosted files: if you choose “Host with AgentReady”, the llms.txt or schema file is served from a public address so your site can point to it.

AI visibility badge: the badge for a domain is public and shows the domain, its latest score and the audit date.

AI referral tracking: the tracking snippet sends an event to AgentReady when a visitor arrives from an AI engine. The collection address is public, so treat the data as an observed signal, not a verified visitor count.

How outbound requests are limited

When AgentReady fetches a page on your behalf (for example to verify an llms.txt file), requests are restricted to public internet addresses. Private, loopback and cloud-metadata addresses are blocked, including when a site redirects to one.

What this page is not

This page describes how the product works today. It is not a certification, an audit report or a contract. If you need a specific control, a data processing agreement or a security questionnaire, ask us.

Questions or a security concern? Contact us. See also the Privacy Policy.