DocsReports and fixes
Your trust page
A public, dated record of what passed, for your customers, and the badge for it.
On this page
In short
- A trust page is a public page for one app. It lists the checks that passed, with the date, and never shows a finding, a score or where a weakness is.
- It needs a confirmed domain, and the app's latest check must have no critical or high finding open when you publish. Only a company admin publishes it.
- You get a link to send to customers, a badge for your own site, and a count of the visits. The report stays with the people fixing things.
Where in the app
Every app's trust page is managed under Trust pages in the Apps section of the company settings. Click the row with your name at the foot of the sidebar, click Settings, then click Apps under Company in the list. Your company shows the menu.
The app's own page has a Trust page card too, in its right column.
Step by step
Open the trust pages
Open Settings from the account menu, click Apps under Company, and find Trust pages. Each app has its own box, with its name and address at the top. On the app's page, Manage in the Trust page card leads here.
Publish it
Click Publish trust page. The button reads Publishing, then the pill turns to Published and the page's address appears. When publishing is not possible yet, a sentence stands in place of the button and says what is missing. The app page's card offers the same button while the page is not out.
Send the link
Click Copy link beside the address and send it to whoever asked. Anyone can open it, without an account.
Put the badge on your site
Under the address, the badge shows as it looks today. Click Copy the badge code and paste the code into your site. The badge links to the trust page.
See who looked
Once the page is out, a line says when someone last opened it, such as Last visit today. It adds the visits of this week and of the last 30 days. A small line under it draws the 30 days. Before the first visit, it reads No visits yet. Share the link or the badge, and the first visit shows here.
The Trust page card on the app's page shows the same line, with the link and Copy link.
Choose whether search engines list it
Let search engines list this page is ticked for every app at first. To keep the page out of search results, untick it and click Save. The page then reaches only people with the link or the badge.
Take it down
Click Take the page down. The pill reads Not published, and the address shows nothing public from then on. Publish again later, and the same address and badge work again.
Only a company admin publishes, takes down or changes the search setting. A member sees the same boxes without the buttons. In place of the button, a line says An admin of this company can publish it. or An admin of this company can take the page down., and the search setting reads as a sentence.
What happens behind the scenes
The trust page rests on the newest check of the app that had no critical or high finding open. It shows that check's date and stays valid for seven days after it. The guardian checks every app each day, so an app without a serious finding renews its page every day.
When a check finds something critical or high, the page does not change at once. It stops renewing, and after seven days it says the record lapsed. That week is yours to fix it, and a page that changed the day a weakness appeared would tell others where to look.
What the page shows:
- A seal and the verdict: Passed Vallit’s security check., with the date of the check and the date the record is valid until.
- Who checked it, since when the app is watched, how many checks ran in the last 30 days, and the day you confirmed the domain.
- What was tested, and passed: the checks that came back clean, grouped by area, one line each. A line says what was not found, such as No form sends passwords unencrypted or in the address. With your code connected, The app’s code adds one line per topic of the code checks that all passed.
- Checked every day: thirty squares, one per day, filled on each day a check ran. They show that checks ran, never what a check found.
- About this check: Vallit checks independently, from outside, and the page is not an audit or a certification.
- Verify this page: the page's own address on app.vallit.net, and where to write if the domain is yours and you did not publish it.
- An address to write to, info@vallit.net, for anyone who says the domain is theirs and did not publish the page.
The lines of the website checks sit in five groups:
| Group | The checks it holds, from What we check |
|---|---|
| Connection and availability | Uptime, the certificate, outdated encryption, the switch from http to https, insecure content and where forms send passwords |
| Protection in the browser | Security headers, the Content Security Policy, session cookies, sign-ins in shared caches, the API’s allowed websites, outside files without a fingerprint and links that forward elsewhere |
| Secrets and exposed files | Exposed keys, keys in links, configuration and password files, backups, admin tools, development servers, the GraphQL API, libraries and the framework version on the pages, and scripts from hijacked domains |
| Customer data and sign-up | The Supabase database, sign-up and file storage, storage that lists its files, and the Firebase database |
| Domain and email | Email in the domain’s name, domain renewal, forgotten subdomains and subdomains others can claim |
Search engine listing has no line, because it says nothing about trust. Under The app’s code, the repository's line covers keys named for the browser and GitHub Actions workflows as well. It reads "No exposed secrets, no libraries with known flaws and no build step outsiders can steer."
What it never shows: a finding, its title, where it sits, a score, a band, or how many checks found something. A check that found something is not among the lines that passed.
Visits
- Vallit counts the visits of a published page per day. It stores the day and the number, and nothing about the visitor: no IP address, no browser, no cookie and no referrer.
- A visit counts when a browser opens the page. Crawlers, link previews in chat apps, scripts and a browser loading the page ahead of a click do not count.
- Anyone signed in to Vallit does not count, so your own look at the page leaves the number as it is.
Search engines
- With Let search engines list this page ticked, the page asks search engines to list it. Unticked, it asks them not to list it and not to follow its links.
- The setting changes nothing else. The link and the badge work either way.
The badge
The badge carries the date of the record and nothing else. It is a plain image without scripts, and it refreshes at most once an hour. Pages and badges live on app.vallit.net, so a copy anywhere else is not ours.
If something goes wrong
| What you see | What it means | What to do |
|---|---|---|
| Confirm your domain first, so a trust page can only come from its owner. | The app's domain is not confirmed yet. | Confirm your domain, then come back to the section. |
| Publish once the first check has finished. | The app has no finished check yet. | Wait for the guardian's first check, or click Run a check on the app's page. |
| Publish once the latest check has no critical or high finding left open. | The newest check found something critical or high. | Fix it, or ask us to under Fixing what we found. The next clean check lets you publish. |
| That app is not in your company. | The app belongs to another company, or it was removed. | Sign in with the account of the company that holds the app. |
| Only an admin can change the trust page. | You are a member of the company, not an admin. | Ask an admin of the company to publish, take down or change the search setting. |
| That did not go through. Try again in a moment. | The search setting was not saved. | Click Save again in a moment. |
| There is nothing here | The trust page is not published, or the address is incomplete. | Publish the page again under Trust pages in the company settings, or copy the whole address with Copy link. |