Skip to content
Why GEO Why us Pricing
Get started free
HomeSecurity

Nothing to install, nothing to hand over.

Praised is a measurement service that reads the public web, so a first run needs a domain and nothing else — no tag on your site, no CMS credentials, no DNS record.

Last updated .

Access to your workspace

What our servers do on the internet

The product fetches other people's pages, which is exactly the capability an attacker would like to borrow. Every outbound fetch — the free checker, the crawler check, the site audit, your own webhook — goes through a guard that resolves the target first and refuses private, loopback and link-local addresses, redirects included. Public tools are rate-limited per IP with a daily ceiling, and the free tools run under a dedicated tenant so anonymous checks never land in a customer's history.

The APIs themselves are rate-limited too: authentication endpoints carry tight per-IP and per-account budgets, and every data endpoint is capped per credential — an unthrottled loop gets a clean 429 with a Retry-After, not a slow database.

Data at rest and in transit

Your data stays yours

What we do not claim

We are not certified against SOC 2 or ISO 27001 today, and we would rather say so plainly than imply a badge we do not have. If a certification is a procurement requirement for you, tell us and you will get a straight answer about the timeline instead of a maybe.

Reporting a vulnerability

Email hello@praised.co with enough detail to reproduce the issue. We acknowledge within two business days, keep you posted while we fix it, and will not threaten anyone who reports something in good faith.

See also the privacy policy, the terms of service, and the measurement methodology.

Frequently asked questions

Can another workspace see my data?
No. Every API request resolves to one workspace, and data access is scoped to it on the query rather than filtered afterwards, so a token for one workspace cannot read another's runs. See Access to your workspace.
How do I get my data out?
Everything a workspace holds — runs, answers, settings and events — exports as JSON from workspace settings, self-serve, at any time. Closing a workspace is self-serve too. Removed products keep a 30-day grace window and are then hard-deleted on schedule. See Your data stays yours.
How do I report a vulnerability?
Email hello@praised.co with enough detail to reproduce the issue. We acknowledge within two business days, keep you posted while we fix it, and will not threaten anyone who reports something in good faith.