complyeah
Agent Readiness

Our Agent Readiness runner

Effective September 3, 2026

The runner tests whether a software agent can understand and navigate your live website. It runs only after ownership of the exact domain is verified and a separate Agent Readiness authorization is active.

How to identify it

Requests identify themselves with complyeah-agent/1.0 (+https://complyeah.com/agent-runner) and a run attribution header. Traffic originates from our fixed worker egress:

    The same address is documented on the security scanner disclosure.

    What it can do

    • Read visible pages with GET or HEAD, follow safe navigation on the verified domain, scroll, open read only controls, and capture evidence screenshots.
    • Respect robots.txt and strict request, page, step, time, and context limits.
    • Visit only the exact verified hostname. Third party and external destinations are blocked.

    What it never does

    • It does not submit forms, log in, send email, purchase, reserve, add to cart, upload, download, or modify data.
    • It does not conduct security exploitation. External security uses a separate runner, authorization, and policy.
    • It does not expose customer cookies, headers, raw prompts, or hidden model reasoning in reports.

    Unexpected traffic

    If you see unexpected traffic that identifies as complyeah, contact support@complyeah.com. We will investigate and stop it.