Skip to main content
EveryRamp home
  • Deadlines
  • How it works
  • Pricing
  • Free scan

Security & data fact sheet

Last updated September 27, 2026. A short, plain-English answer to the questions a security or procurement review usually asks. Our accessibility conformance report covers the same standard we test your site against, applied to our own website and deliverables.

Hosting and where your data lives

EveryRamp runs entirely on Cloudflare, in the United States: our website, our database, our file storage, and the browser we use to crawl and screenshot your pages. We do not run our own servers. Traffic to and from our website and your private report link is encrypted in transit (HTTPS/TLS). Cloudflare encrypts stored data at rest on its own infrastructure.

Access to your results

Your test report and fix pack live at a private link: only someone with that link, or the owner, can open them. We do not publish your results, your organization's name, or your website address without your permission. See our privacy policy for exactly how long we keep each kind of information.

Subprocessors

We use a small, fixed set of subprocessors, all Cloudflare products running in Cloudflare's own infrastructure — we do not add a new one without updating this page:

  • Cloudflare — hosting, our database, file storage, email routing for hello@everyramp.com, and Browser Rendering (the headless browser that loads your pages to test them).
  • Cloudflare Workers AI — the AI models that write plain-English descriptions, suggested fixes and rebuilt PDF text. As of this writing: Meta Llama 4 Scout, Mistral Small 3.1, Meta Llama 3.3, and Qwen2.5-Coder. We have not confirmed HIPAA eligibility for these models. That is one reason we ask every customer not to send us real patient data — see Health information in our privacy policy.

Not a HIPAA business associate

EveryRamp is not a HIPAA business associate, and we do not sign business-associate agreements today. We test only public, unauthenticated pages and documents; we have no way to see anything behind a login. Do not send us, or link us to, real patient data. See terms of service and privacy policy for the full clauses.

If something goes wrong

We follow a written incident-response policy: it says who is told and how fast. If a security incident exposes your information, we tell you by email within a few business days of confirming it. See our privacy policy for the full commitment.

Who reviews our code

EveryRamp is a small, automated product, but changes to it are not shipped unreviewed. Every change goes through independent code review before it reaches customers, covering security, network safety, job reliability, our database, PDF rebuilding, AI safety, escaping and injection, our own site's accessibility, the truthfulness of every claim we make, privacy, limits and failure states. As of this writing the product has been through 44 rounds of that review.

What we don't do

We do not use advertising trackers on our website. We do not sell or rent your information. We do not change your website ourselves — your web team applies the fixes we write.

Questions

Email hello@everyramp.com with any security or procurement question. We answer in writing, and a templated first answer usually comes back the same day.

Need our Form W-9 or certificate of insurance for your vendor file? Email hello@everyramp.com and we will send them.

© 2026 Everyramp LLC. Questions: hello@everyramp.com. We work by email, so you get answers in writing.

Terms of service · Privacy · Security · Conformance · About · Guides · Sample report