See how any business shows up in ChatGPT, Gemini and more
Run a free AI visibility audit
Insites
AEO & SEO
AI Search
AI Visibility Monitoring
AI
Track how a business is cited in ChatGPT, Gemini & Perplexity over time
SEO & AEO Audit
Titles, meta, headings, schema and the on-page factors AI reads
Local SEO
Listings, NAP accuracy, reviews & Google Business Profile
Rank Tracking
Monitor keywords, search volumes & ranking changes
Local Grid
Visualise how a business ranks across their local area on a search grid
AI Keyword Planner
AI
Keyword suggestions powered by AI - skip the expensive tools
Learn
What is AEO?
Answer Engine Optimisation explained - the new SEO for AI search
AEO Guidebook
The definitive guide to Answer Engine Optimisation for local businesses
AI Visibility Report 2026
New
10,000 local businesses analysed for AI search readiness
AI Visibility
Is your local business client visible to AI?
See how any business is cited and recommended in AI search engines like ChatGPT, Gemini, and Perplexity, and track it over time.
Explore AI Visibility
Agentic Workflows
Build Your Own
MCP Server
AI
Give your LLM real audit data - run checks directly from ChatGPT or Claude
REST API
Full programmatic access to trigger audits and retrieve results
Webhooks
Real-time events when audits complete - push data to your stack
Ready-Made Integrations
Salesforce
Trigger AI & SEO audits and view results inside your CRM
HubSpot
Sync AEO & SEO audit data with contacts and deals automatically
Zapier
Connect Insites AEO & SEO data to 5,000+ apps with no-code workflows
Duda
AI
AI-generate websites and audit builds inside Duda
All integrations
Browse every tool Insites connects with
Agentic Workflows
Power your AI with real audit data
Connect Insites to your AI tools. Run audits, research prospects, and draft personalised outreach - all from your LLM.
See what you can build
Platform
Features
Paige Agent
Your built-in AI assistant - talking points and answers for any finding
Customise Your Audit
Design your audit and pick from 70+ checks to match your services
White-Label Audits
Add your logo, colours and domain so every audit goes out as your brand
Local Grid
Visualise how a business ranks across their local area on a search grid
Lead Generation Widget
Embed an audit form on any site and capture inbound leads
All Features
Browse every feature in the Insites platform
Use Cases
Sales Teams
Prepare for calls, audit at scale, prioritise your pipeline
Lead Generation
Widget embed, campaign-driven audits, inbound capture
Retention & Upsell
ROI reporting, progress tracking, churn reduction
Agentic Workflows
AI
The data layer that powers your AI agents and automations
Website Builders
Build quality, staging audits, client sign-off
Resellers
White-label the platform and resell branded audits
The Platform
Every tool your team needs. One platform.
Website audits, white-label reports, batch processing, and competitor analysis - built for agencies and enterprises that need to move fast.
Explore the platform
Why Insites
Industries
Marketing Agencies
Local marketing agencies selling digital services
Hosting & Registrars
Web hosts and domain registrars
Directories
Yellow Pages and local directories
Media
TV, radio, and newspaper groups
Telecoms
Telecoms, broadband, and mobile providers
SaaS
Vertical SaaS providers
Case Studies
Gargle
Doubled agency size in 2 years with Insites audits
WordJack
BDR productivity up 50%, tripled demo bookings
Robin
46% increase in order value, 500 new leads per month
Yell
Boosted sales confidence and reduced build time by 20%
FCR Media
10x conversion on marketing campaigns
Herold
Tripled click-through rate, doubled revenue per account
Why Insites
Trusted by 200+ agencies in 40+ countries
See how sales teams, agencies and marketers use Insites to close more deals and deliver better results.
Read success stories
Resources
Guides & Reports
AI Visibility Report 2026
New
We analysed 10,000 local businesses for AI search readiness
AEO Guidebook
The definitive guide to Answer Engine Optimisation for local businesses
What is AEO?
Answer Engine Optimisation explained - the new SEO for AI search
From Insites
Product Updates
New
What's new at Insites - the latest features, every month
Blog
Insights on AI visibility, sales, and digital auditing
FiveInsites Newsletter
Five actionable insights delivered to your inbox every week
About Insites
Our story, mission, and team
Free Checkers
Free AI Visibility Check
AI
See how a business shows up in ChatGPT, Gemini & Perplexity - instantly
Free EEAT Checker
Score a site's Experience, Expertise, Authority & Trust signals
Free Tool
Try an AI visibility audit - free
Run an AI visibility audit on any website. See how a business appears in ChatGPT, Gemini, and Perplexity - no sign-up required.
Run a free audit
Book a Demo
The local AI visibility intelligence platform
Book a Demo
Sign in
Book a Demo
Legal

Vulnerability Disclosure

Overview

Insites is committed to maintaining the security, integrity and availability of our systems, and to protecting our customers' data.

We do not operate a bug bounty programme, and we do not invite, commission or consent to security testing of our platform. This policy exists so that if you become aware of a vulnerability affecting Insites, there is a clear and proper way to tell us about it, and so that the limits we expect to be respected are set out in advance.

It explains what a report must contain, what we will do with one, and what we will not accept.

Permission and Safe Harbour

This policy is not permission to test. Nothing in it authorises you to access, probe, scan, disrupt or interfere with our systems, our customers' data, or any account that is not your own. Activity outside this policy is unauthorised, and we reserve all rights and remedies in respect of it.

Where you report a vulnerability to us in good faith and you have stayed within the limits below, we will not pursue legal action against you in respect of that report. This applies where you:

  • Acted in good faith, with no intent to extort, disrupt, or profit.
  • Stopped as soon as you had enough to demonstrate the issue, and went no further.
  • Accessed no more data than was strictly necessary, and did not retain, copy or share any of it.
  • Caused no degradation to our service and no harm to our customers.
  • Reported the issue to us promptly and privately, and kept it confidential.

This protection is limited to the conduct described above. It does not extend to anything beyond it, and it does not apply where these conditions are not met.

If a third party brings legal action against someone who complied with this policy in full, we will confirm that their report was made in accordance with it.

Scope

We will accept reports about:

  • Public-facing web applications operated by Insites.
  • Domains owned and controlled by insites.com.
  • Public APIs and documented endpoints.
  • Customer-facing dashboards and services.
  • Authentication and authorisation mechanisms.

Listing an asset here describes what we are willing to receive a report about. It is not permission to test that asset.

The following are never acceptable and fall outside this policy entirely:

  • Social engineering or phishing targeting our employees, contractors, or customers.
  • Physical security testing.
  • Denial-of-service attacks, stress testing, or anything that degrades performance for others.
  • Automated scanning that generates significant traffic.
  • Testing against third-party services not owned or operated by Insites, including the websites our customers submit for analysis.
  • Accessing, modifying or exfiltrating another user's data.
How to Report a Vulnerability

Email security@insites.com.

Your report must contain enough detail for us to reproduce the issue. As a minimum, tell us:

  • The affected URL, API or component.
  • What the vulnerability is.
  • Step-by-step instructions to reproduce it.
  • What someone could actually do with it, and why that matters.
  • Any supporting evidence, such as proof-of-concept code, screenshots or logs.

Reports without that detail will not be answered. In particular, we do not respond to:

  • Messages stating that a vulnerability exists without saying what it is.
  • Requests to agree a reward, or to confirm a bounty, before details will be shared.
  • Raw output from an automated scanner, sent without analysis.
  • Reports of findings with no demonstrated security impact, such as missing headers or configuration preferences.

We will not enter into any negotiation about payment in exchange for details of a vulnerability.

Please keep the issue confidential and do not disclose it publicly until we have had a reasonable opportunity to remediate it.

What We Will Do

Where a report meets the requirements above, we aim to:

  • Acknowledge it within five working days.
  • Triage and validate the issue.
  • Tell you how we have assessed its severity and what we intend to do about it.
  • Remediate confirmed vulnerabilities on a timescale proportionate to their severity and to the risk they present.

These are aims rather than commitments, and they do not apply to reports that fall short of the requirements above.

Coordinated Disclosure

We expect a vulnerability to remain confidential until remediation is complete and our customers are protected. Once an issue is resolved we are willing to discuss whether and when it can be described publicly. We do not accept disclosure deadlines set unilaterally, and publishing before we have remediated falls outside this policy.

Rewards

We do not operate a bug bounty programme. We may choose to acknowledge a researcher who has made a genuinely useful report, entirely at our discretion. Nothing in this policy creates any expectation or entitlement to payment, recognition or reward.

Limits We Expect to Be Respected

If you do become aware of a vulnerability:

  • Do nothing that affects the availability or performance of the service.
  • Do not access or retain sensitive customer data.
  • Stop immediately and tell us if you encounter customer data unintentionally.
  • Do not attempt to create or obtain an account. Accounts are provisioned to our customers, and there is no self-service sign-up. If you are a customer, stay within your own account and your own data.
  • Do not attempt lateral movement, privilege escalation, or persistence beyond what is needed to establish that the issue is real.
Legal Terms

By reporting a vulnerability to us, you confirm that you have complied with all applicable laws and regulations, that you have not exploited the issue for financial gain or any malicious purpose, and that the detail you have provided is accurate.

Reporting an issue to us does not entitle you to any payment, and does not transfer to you any right in our systems or data.

Updates to This Policy

We may update this policy from time to time to reflect changes in our security practices. The version on this page is the current one.

Contact

Security team: security@insites.com.

Insites
Platform audits
SEO & AEO Audit
Local SEO
Speed & Performance
Accessibility
Compliance
Content & UX
Ads Audit
Social Media Audit
Rank Tracking
All Audits
Features
AI Visibility Monitoring
Customise Your Audit
White-Label Audits
Prospecting at Scale
Competitor Audit
Local Grid
AI Keyword Planner
Paige Agent
AI Email Generator
Sharing & Export
Integrations
All Integrations
MCP Server
REST API
Webhooks
Salesforce
HubSpot
Zapier
Duda
Alternatives
marketgoo Alternative
BuzzBoard Alternative
WooRank Alternative
SE Ranking Alternative
Local Falcon Alternative
BrightLocal Alternative
Peec AI Alternative
Profound Alternative
Otterly.AI Alternative
Rankscale Alternative
Use Cases
Sales Teams
Lead Generation
Retention & Upsell
Agentic Workflows
Website Builders
Resellers
Industries
Marketing Agencies
Hosting & Registrars
Directories
Media
Telecoms
SaaS
Resources
Blog
Product Updates
Success Stories
AI Visibility Report
AEO Guidebook
Free AI Audit
FiveInsites Newsletter
Company
About Insites
Pricing
Careers
Contact
Insites is a registered trademark of Insites Technologies Ltd. Insites is registered in England and Wales. Company no: 13479874. VAT: GB 384 0954 73, EU 372 0467 67.
Privacy Terms Cookie Policy Legal