This disclaimer is current and in effect. It describes the product as it works today, including paid plans, and is still under review by a lawyer; we will post any revisions here.
Disclaimer
Plaintext is a tool that helps you spot common security mistakes. It is not a full security audit, and a result from it is not a promise that your app is safe. Please read this before you rely on anything it tells you.
What Plaintext does
Plaintext looks for a set of known problems in what a site makes publicly reachable. It reads the pages and JavaScript that a normal browser already receives, and it checks them against the list of issues shown on the site. It does not sign in, submit forms, attack your service, or reach anything behind a login.
Because the check is passive and only sees what is public, it can miss problems that live in your server code, your database rules, or any part of the app it never sees. It is a fast first look, not a substitute for a hands-on review by a security professional.
What a result means
A scan that finds nothing means we found nothing in what we tested at the moment we tested it. It is not a guarantee that your app is safe. We never present a clean result as proof of security.
- New issues can appear the next time you ship a change.
- Problems we do not check for can exist regardless of your result.
- A finding is our best assessment from the outside and can, in rare cases, be a false positive.
Treat the report as a starting point. Confirm anything important in your own code before you act on it, and re-scan after you make changes.
No warranty
The service and every report are provided as is and as available, without warranty of any kind, whether express or implied, including any implied warranty of accuracy, fitness for a particular purpose, or that the service will be uninterrupted or error free.
No certification
A Plaintext report is our own assessment. It is not a certification, it does not come from an accredited auditor, and on its own it satisfies no compliance standard such as SOC 2, PCI DSS, GDPR, HIPAA, or ISO 27001. Do not present a report as evidence of compliance with any of these.
Limitation of liability
To the fullest extent the law allows, Plaintext and the people who build it are not liable for any breach, loss, downtime, or damage arising from your use of the service or your reliance on a result. You are responsible for the security of your own applications. The limits and responsibilities in the Terms apply to this Disclaimer as well.
Last updated: 2 August 2026