comment_

Security

Last updated 11 September 2026.

Comment is an early-access product built by a very small team. The most useful thing this page can do is tell you exactly which controls exist and which do not, so your review ends with a decision instead of a follow-up email.

The first control is not collecting it

Most of the risk in this product category comes from what the tool records. Comment takes no screenshot, keeps no copy of your page text, and never sees a keystroke, a pointer path, or a URL query string. Data that was never captured cannot leak, be subpoenaed, or be mishandled by us. The full inventory is in the privacy notice.

What is captured is scanned before storage: email addresses, JSON web tokens, payment card numbers, and well-known API-key formats are masked, and a workspace can add its own deny-terms. The audit record says a value was removed and which rule removed it, never the value.

What we do

In transit and at rest

Accounts and access

On your website

Abuse and evidence

What we do not do yet

None of this is on a promised date. It is here so you can decide whether the gaps matter for your use.

Reporting something

Email security@commentunderscore.com. Tell us what you found and how to see it; we will acknowledge within three working days and keep you posted until it is closed. We will not take legal action against anyone who reports a problem in good faith, tests only against their own account, avoids other people's data, and gives us a reasonable chance to fix it before going public.

If a breach affects your data, we will tell you without undue delay after we become aware of it, with what we know at the time. That commitment is written into the DPA rather than left as an intention.