Chrome extension

Privacy policy

HeaderSec scans a website only after you choose Scan security headers. The extension sends the website's public origin to HeaderSec so our server can inspect its public HTTP response headers.

Last updated: July 21, 2026

Data the extension handles

  • Website origin: the scheme, hostname, and port of the active website, such as https://example.com.
  • Public scan data: public response headers, redirects, status information, findings, score, and timing produced by HeaderSec's server-side scan.
  • Locally saved result: the extension remembers the most recent origin, scan time, grade, score, failed and warning counts, up to four finding titles, and report ID so it can restore that result when reopened on the same origin. It does not save full response headers or redirects in Chrome storage.
  • Optional account data: if you sign in with GitHub, HeaderSec receives the GitHub profile and verified email needed to create or connect your HeaderSec account. The extension receives your display name, email, team name, and a short-lived HeaderSec access token.

The extension does not send page content, cookies, passwords, form entries, URL paths, query parameters, fragments, or your general browsing history. It does not install a content script.

How data is used

We use this data only to perform requested scans, display and retain scan reports, associate scans with your account when signed in, enforce service limits, prevent abuse, secure authentication, and operate HeaderSec. We do not sell extension data, use it for advertising, or use it to determine creditworthiness or lending.

A scan report may be available to anyone who has its hard-to-guess report URL. Do not scan a public origin if you do not want that origin and its public security headers included in a report.

Storage and sharing

The extension stores its latest result summary, access token, and basic account display information in Chrome's local extension storage. The saved result is shown only when the active website has the same origin. Extension access tokens expire after 24 hours and can be revoked by signing out. Scan and account records are stored by HeaderSec to provide the service and protect it from misuse.

HeaderSec relies on service providers only where needed to operate the product: Cloudflare for hosting, storage, security, and verification; GitHub for optional sign-in; and Amazon Web Services for transactional account email. A target website also receives HeaderSec's server-side HTTP request when you ask us to scan it.

Your choices

You can scan anonymously, avoid GitHub sign-in, sign out to revoke the extension token, clear the extension's local storage by removing it, or uninstall the extension at any time. To request access, correction, or deletion of account or scan data, email [email protected].

Security and policy

HeaderSec uses encrypted HTTPS connections, narrow Chrome permissions, short-lived scoped tokens, PKCE OAuth, request limits, and server-side target validation. Our use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Contact

HeaderSec is operated by ViWeb Technology. Privacy, security, abuse, and support questions can be sent to [email protected].

Visit HeaderSec extension support.