clickwalker

Security

Last updated October 7, 2026

Clickwalker runs an AI agent against your website, so we keep what it can do narrow and easy to reason about. This page covers how the agent is limited, where data goes, and how to report a problem.

What the agent can do

Claude controls the browser through seven actions: click, type, press a key, scroll, wait, open a page and finish. That’s the whole list. The agent can’t run its own scripts, and it only sees your site through the pages a customer would see.

Every run starts in a fresh browser session, with no logins, cookies or saved data carried over from earlier runs.

It stays on your site

The agent can only navigate to addresses on the domain you gave us. Any other address is refused. If a click ever leads off your site, the agent is warned on its next step and told to stay on the site under test.

Test data only

Flows use test accounts and test payment details, like the 4242 4242 4242 4242 test card. The agent is instructed never to enter real personal or payment details, and password fields are masked in what it reads from the page. Please don’t give us real customer credentials.

Page content is treated as data

Text on a web page could try to give the agent instructions. The agent is instructed to treat everything on the page as something to check, never as instructions to follow, and it can only act through the seven actions above.

Where data goes

Screenshots and page text captured during a run are sent to Anthropic’s API, which runs the Claude model behind the agent. Alerts go to the Slack channel or email address you choose. Cloudflare hosts this website. All of these connections use HTTPS.

We keep run data only as long as we need it to show you reports, and we delete it whenever you ask. The privacy page has the details.

Reporting a vulnerability

If you think you’ve found a security issue in Clickwalker or this website, email hello@clickwalker.com with “Security” in the subject and the steps to reproduce it. We read every report and will reply. Please don’t access data that isn’t yours or disrupt the service while testing.

Our contact details are also published in security.txt.