Security

Last updated 2026-09-29

The short version is that there is very little here to steal. Organic Upside has no accounts, no passwords and no payments, and it never asks for any. This page says what that leaves, how the site is put together, and how to tell us if you find a hole.

What we hold

Your scenario stays in your browser. The numbers you type live in the page and in your browser's local storage. Clearing site data removes them. A share link carries the scenario inside the link itself, so treat a share link the way you would treat the numbers in it: anyone who has the link can read them.

Three things do leave, and only when you ask. The live lookup sends the phrases that still need volumes to our function, which passes them to DataForSEO. A Cloudflare Turnstile check sends Cloudflare a token and your IP address to confirm you are a person. The contact form sends your name, address and message through Resend to our mailbox. Nothing else from your scenario goes anywhere. The privacy page covers each of these in detail.

Counts, not content. The daily lookup allowance and the contact form's per sender limit are enforced with counters stored against a hashed form of the IP address, never the address itself, and they expire after 48 hours. The operator page that reads them holds counts only, with no phrases, addresses or message text.

How the site is built

Static HTML on Cloudflare Pages, with two small functions for the contact form and the lookup. There is no database, no server-side session and no user-supplied content published anywhere on the site.

Every response carries a strict Content Security Policy. Scripts may only come from this origin, Plausible and Cloudflare's Turnstile; there is no inline script and no eval. The page may not be framed, MIME types are not sniffed, referrers are trimmed across origins, and camera, microphone, geolocation, payment and USB are all switched off at the policy level. Plain HTTP redirects to HTTPS, and the site sends an HSTS header asking your browser to remember to use HTTPS on its own.

The contact form has a honeypot field, a timing trap, an origin check and a cap of three messages per sender per day. Submissions caught by any of those get an ordinary success response, so a bot learns nothing from the reply. The lookup is capped per visitor and per day, and fails closed if a secret or a binding is missing, because failing open there would cost money.

The operator dashboard is behind a token, sends noindex and no-store, and is excluded in robots.txt.

Reporting a vulnerability

Please tell us through the contact form. Include enough detail to reproduce the problem: the URL, what you sent and what came back. We will acknowledge inside three working days and tell you what we intend to do.

We do not run a bug bounty and we have no money to pay for reports. What we will do is fix the thing, and credit you on this page if you want the credit.

While you are looking, please stay within testing that does not harm anyone: no denial of service, no automated scanning heavy enough to affect other people, no social engineering of anyone connected with the site, and no access to, modification of, or retention of data that is not yours. Report what you find rather than exploiting it. If you keep to that, we will treat your research as authorized and we will not pursue you for it.

What we do not claim

There is no third party penetration test, no SOC 2, and no ISO certification. This is a free calculator run by a small company, and the honest security story is that it holds almost nothing rather than that it is fortified.