Isolated browser contexts
Each run uses a fresh context, and pages, contexts, traces, and temporary artifacts are closed in cleanup paths.
Monitoring boundaries and security
CartVigil tests public customer-facing pages in an isolated browser context and stops before placing an order. It never needs payment credentials or customer data.
14-day Pro trial · No card required · Setup with only your store URL
Access model
The monitor has the same public view as a guest shopper. Store ownership or explicit authorization is required before onboarding.
Technical controls
Each run uses a fresh context, and pages, contexts, traces, and temporary artifacts are closed in cleanup paths.
Arbitrary URLs must pass SSRF, DNS, IP-range, redirect, and response-boundary checks before production monitoring.
Secrets, cookies, authorization data, payment data, and full synthetic addresses are excluded from logs and displayed evidence.
When production monitoring is enabled, a blocked storefront can allowlist the configured static monitoring IP rather than bypassing protections.
Public CartVigil traffic uses TLS. Application secrets remain server-side, and retained evidence follows explicit storage and deletion policies.
Customer resources are accessed with workspace context; global administration uses separate protected repositories and audited actions.
Retention
Successful runs normally retain structured metrics rather than screenshots. Failed evidence is retained only according to policy.
Current limitations
Security claims are limited to the controls the product actually implements; CartVigil does not display unsupported compliance badges.
CartVigil does not bypass CAPTCHA, WAF, rate limits, bot challenges, or access controls.
Mobile and tablet profiles are browser emulation, not a physical-device farm.
Highly customized or protected purchase flows may be classified as unsupported or blocked.
Results describe the monitored profiles and time of each check, not every customer, location, or browser.
To report a security issue responsibly, email security@cartvigil.com. Do not include secrets or customer data in the first message.
Start with a public URL
No card required. No Magento Admin or source-code access.