Your site
Discovery, audits, consent banners, enforcement, remediation, and the admin UI execute on your WordPress host and in visitors' browsers.
Assure is a technical compliance plugin that runs on your WordPress installation. Audit results, evidence, settings, and visitor consent preferences are stored locally. The plugin does not send usage telemetry to ncdLabs.
Discovery, audits, consent banners, enforcement, remediation, and the admin UI execute on your WordPress host and in visitors' browsers.
Audit results, evidence, activity logs, and plugin settings live in your WordPress database. Installed framework pack catalogs are stored under wp-content/uploads/assure/frameworks/.
Depending on how you configure Assure, the plugin may keep:
When using the native consent banner, visitor consent choices are stored in the visitor's browser (localStorage) on your site's origin.
The Assure plugin does not send usage statistics, error reports, or analytics to ncdLabs. Discovery and audit scans request your own site's public pages and REST API; those results are not uploaded to ncdLabs.
wp-content/uploads/assure/. This cannot be undone.
Assure contacts external services only in the cases below — and only when you use the related feature.
When you import a purchased compliance pack, Assure sends your unlock key, framework identifier, and site URL to verify the Stripe purchase and bind the license to one site.
https://ncdlabs.com/products/assure/api/activateWhen importing a pack, Assure may call the ncdLabs provisioning API to enable hosted browser verification. If configured, audits and discovery may send scan targets to your browser verification service.
https://ncdlabs.com/products/assure/api/browser-verification/provisionhttps://browser-verify.ncdlabs.comWhen you connect Google Analytics from Manage → Integrations, Assure may use Google OAuth and the Google Analytics Admin API. If you have not configured your own OAuth client, Assure uses an ncdLabs OAuth proxy.
https://ncdlabs.com/products/assure/api/google/oauth/start and .../exchangeaccounts.google.com, oauth2.googleapis.com, www.googleapis.com, analyticsadmin.googleapis.com, tagmanager.googleapis.comWhen an administrator deactivates the plugin, WordPress may show an optional feedback dialog. You can skip it and deactivate without answering. Closing the dialog cancels deactivation.
If you choose Submit & deactivate, the plugin emails your selected reason and any
comments you type to feedback+assure@ncdlabs.com
using your site’s normal WordPress mail configuration (wp_mail). Feedback is used only to
improve the product.
A separate checkbox (unchecked by default) lets you include diagnostic versions with that email: plugin version, WordPress version, and PHP version. Your site URL and admin email are never included. If you leave the checkbox unchecked, only the reason and comments you entered are sent.
Pack purchases, licensing API calls, and optional OAuth proxy traffic are handled under the ncdLabs site privacy policy. Stripe processes payments under Stripe's privacy policy.
Email privacy questions about Assure or pack licensing.