Monitoring boundaries and security

Monitor the storefront, not the business behind it.

CartVigil tests public customer-facing pages in an isolated browser context and stops before placing an order. It never needs payment credentials or customer data.

14-day Pro trial · No card required · Setup with only your store URL

Access model

Start without sensitive system access.

The monitor has the same public view as a guest shopper. Store ownership or explicit authorization is required before onboarding.

  • RequiredPublic storefront URL and monitoring authorization
  • Not requiredMagento Admin, API keys, or module installation
  • Not requiredSource code, production logs, analytics, or customer records
  • Never enteredCard numbers, payment credentials, or Place Order

Technical controls

Bound the browser and the data it can reach.

Isolated browser contexts

Each run uses a fresh context, and pages, contexts, traces, and temporary artifacts are closed in cleanup paths.

URL and network safety

Arbitrary URLs must pass SSRF, DNS, IP-range, redirect, and response-boundary checks before production monitoring.

Redacted evidence

Secrets, cookies, authorization data, payment data, and full synthetic addresses are excluded from logs and displayed evidence.

Static IP allowlisting

When production monitoring is enabled, a blocked storefront can allowlist the configured static monitoring IP rather than bypassing protections.

Transport and storage

Public CartVigil traffic uses TLS. Application secrets remain server-side, and retained evidence follows explicit storage and deletion policies.

Tenant boundaries

Customer resources are accessed with workspace context; global administration uses separate protected repositories and audited actions.

Retention

Keep operational evidence for a bounded period.

Successful runs normally retain structured metrics rather than screenshots. Failed evidence is retained only according to policy.

24 hoursSuccessful temporary screenshots
30 daysFailed screenshots by default
14 daysPlaywright traces and application logs
90 daysCritical incident evidence, configurable

Current limitations

What CartVigil will not do.

Security claims are limited to the controls the product actually implements; CartVigil does not display unsupported compliance badges.

No protection bypass

CartVigil does not bypass CAPTCHA, WAF, rate limits, bot challenges, or access controls.

No real-device claim

Mobile and tablet profiles are browser emulation, not a physical-device farm.

No universal compatibility

Highly customized or protected purchase flows may be classified as unsupported or blocked.

No absolute availability guarantee

Results describe the monitored profiles and time of each check, not every customer, location, or browser.

To report a security issue responsibly, email security@cartvigil.com. Do not include secrets or customer data in the first message.

Start with a public URL

Find out whether your customers can still buy.

Start monitoring free

No card required. No Magento Admin or source-code access.