None of this was found by an outage,
a complaint, or a researcher.
It was found by asking one question, systematically, across every product: does what we claim match what the code actually does?
A security tool that silently lied. When the scanning backend failed or timed out, it didn't show an error — it reported "Safe." Every time. Nothing was checked, but users were told everything was fine.
Live for months. The policy said data was "processed locally." It wasn't — content was sent to a third-party AI API. The claim was written once; the architecture changed later. Nobody went back.
"Success" that never arrived. The contact form returned a success message. Nothing was delivered — it posted to a dead URL, left over from a hosting migration months earlier.
The parent entity itself. The company running shared analytics across six products had no privacy or terms page — just a link that silently served the homepage.