Security

Security and responsible capture

Stravue opens public web pages and takes a picture of them, because a customer asked it to. This page explains how it behaves, what it will never do, and how to reach a person.

If our traffic is a problem for your site

Email support@stravue.com and we will stop capturing your site. No form, no argument, no justification needed. We would rather lose the page than be a nuisance.

Security reports go to security@stravue.com. Machine-readable contacts are at /.well-known/security.txt.

How Stravue visits a page

  • A real browser loads the page once, the same way a person would, and takes a full-length screenshot on desktop and phone.
  • Requests to the same site are spaced out. Stravue paces itself so a capture arrives as a visit, never as a burst.
  • Only public pages. Stravue does not log in, does not accept invitations, and does not pass paywalls.
  • Captures happen because a customer asked for that specific address. Stravue does not wander a site looking for more.

What Stravue will never do

  • Scan networks or IP addresses. Stravue requests web pages over HTTPS and nothing else.
  • Solve or defeat a verification challenge. If a site says no, the customer is told it said no, and gets an honest empty result rather than an invented one.
  • Collect personal data, or capture anything behind a login.
  • Use a fake source address, or hide who to complain to.

Reporting a vulnerability

Stravue is run by one person, so there is no bounty programme and no triage team. What there is: a reply. Send the detail to security@stravue.com and give it a reasonable window before publishing. Anything affecting customer data gets worked on the day it arrives.

See also Privacy and Acceptable use.